At a glance
- Customer information is used to arrange and provide care, manage bookings and communicate with you.
- Public photos are optional. Saying no does not prevent enrolment.
- Planned CCTV is for internal security and incident review, with a normal 14-day retention period.
- Ask Aimee or Ash about your information at info@waggleroom.co.nz.
This is a quick guide. Please read the detail below before agreeing.
1. Who is responsible
Waggle Room Limited (NZ company number 9452343), 1/38 Keeling Road, Henderson, Auckland, is responsible for information collected for its daycare and website. Contact Aimee Camplin or Ash Bahadori at info@waggleroom.co.nz and mark your message “Privacy”. Aimee and Ash coordinate privacy requests.
Online account registration, email verification, password recovery, dog enrolment, vaccination uploads and meeting requests are available. Booking, payment, warehouse and AI-report features are not yet enabled online. Sections about those future services describe proposed practices and will be checked before activation.
2. Information we collect and why
Provide only information needed for the request or your dog’s care. You do not need an account to ask for a meet-and-greet, and can provide a phone number or email address. You can decline optional photos and marketing. Without information necessary for safe care or account administration, we may be unable to confirm the relevant service; we will explain what is needed.
- Enquiries: your name, chosen contact details, your dog’s name and the message you provide, so we can reply or arrange a meeting.
- Accounts and enrolment: name, email, phone, address, login credentials, emergency contacts, authorised collectors and recorded agreements, to manage your account and safe handover.
- Dog care: age, vaccination evidence, assessment outcomes, health, behaviour, allergies, feeding/medication instructions, other care providers and visit records, to assess suitability and provide agreed care.
- Bookings and payments: visits, check-in/out, credits, purchases, refunds, outstanding balances and payment references, to manage availability, accounts and disputes.
- Optional or service-specific details: public-photo choices; home-access instructions only if pickup is agreed; and CCTV or report recordings only as described below.
3. Where information comes from
We normally collect information from you through forms, conversations, uploaded documents and your account. Staff add assessments, attendance, care notes and incident records. We may receive relevant information from a named emergency contact, authorised collector, treating vet or another source where authorised or otherwise permitted by law.
Before naming another person, please tell them why you are providing their details and share this notice. That helps us contact them appropriately but does not transfer our privacy responsibilities to you. Where required, we take reasonable steps to notify people whose details we receive indirectly, unless a lawful exception applies.
4. Use, communications and optional photos
We use information to respond to you, assess and care for your dog, manage bookings and credits, record incidents, resolve complaints, secure the service and meet legal obligations. We do not sell customer information.
Account verification, account invitations and password-reset emails are delivered through Resend. Meeting requests are saved to Aimee’s administrator inbox for personal follow-up. Automated booking reminders, text messages and visit-report emails are not enabled online yet; those are planned services.
Public use of your dog’s photo on the website or social media is a separate optional choice. Refusing does not prevent daycare. Tell us if you withdraw permission; we will stop new use and remove material we control where reasonably practicable. We cannot guarantee removal of copies already shared by others. We avoid publishing owner identities, contact details or location information with dog photos without separate permission.
Daycare enrolment does not automatically subscribe you to marketing. If marketing is offered later, we will explain it separately and provide a way to opt out.
5. Who can access information
Access is limited to people who need the information for their role. Aimee and Ash manage customer and administrative matters. Authorised carers, including Mum, need relevant care and handover information. The warehouse staff display shows dogs present, expected collection times, care instructions and record-check alerts; it is intended for staff viewing, not public streaming.
We may share necessary information with your authorised contacts, a treating vet, service providers helping operate the business, professional advisers or insurers dealing with a relevant matter, and authorities where legally required or permitted. We limit what is shared to the relevant purpose.
For agreed home collections, keys and entry codes are restricted to Aimee and Ash. Do not place codes in general enquiries or visit reports. A secure method for providing, storing and returning/deleting access details must be agreed before home pickup begins.
6. Storage, service providers and overseas processing
The online website runs on Vercel. Supabase manages account authentication and a private PostgreSQL database configured in Sydney, Australia. Dog details, submitted agreements, meeting requests and vaccination files are stored in that private database. The website checks your signed-in identity and role before returning private records; customers can access their own household’s records.
Resend processes recipient email addresses and account-link messages to deliver verification, invitation and password-reset emails. Google Workspace handles our business mailbox correspondence. These providers may process service data outside New Zealand. The database’s Sydney setting is not a promise that all provider processing occurs in Australia. Stripe, SMS and AI reporting are not enabled in this online account release. Formspree is used on the earlier Aimee website, not these forms.
Only information needed for the relevant service is sent to each provider. Provider contracts, retention settings, backup arrangements and any applicable overseas-disclosure requirements remain part of the review before the full daycare service opens. Contact Aimee or Ash if you want to discuss these arrangements before submitting information. Accepting care terms does not waive privacy rights.
We use access controls and passwords and aim to limit access to authorised people. No system can be promised completely secure. Live backups, deletion processes and provider security must be verified before launch.
To finalise: Full-service launch check: finalise backups, retention and provider safeguards; identify SMS and AI arrangements before enabling them.
7. Cookies and browser requests
The website uses a secure sign-in cookie with a maximum seven-day session lifetime. Signing out ends that session; resetting your password through this website invalidates earlier website sessions. Blocking the cookie prevents normal account use. Request counters limit repeated sign-in and email attempts. There are no advertising or analytics integrations in this build.
The website currently loads its fonts from Google Fonts. Your browser contacts Google to retrieve those files, which exposes connection information such as your IP address to that service. Opening email links or other external links takes you to services with their own privacy practices.
If tracking, analytics or additional third-party resources are introduced, we will update the notice and make any required choices available before those services are used.
8. CCTV at the daycare — planned
CCTV is planned for internal security and incident review. It is not a customer livestream or a source of marketing footage. Signs will identify monitored areas before people enter. Camera positioning and audio settings must be checked before activation; the proposed setup is video only, without routine audio recording.
Routine access is restricted to Ash, Aimee and Mum. Relevant footage may be shared for a lawful purpose, such as investigating an incident, handling an insurance claim or responding to a valid legal request. We consider the privacy of other people before releasing footage.
The intended normal retention period is 14 days, followed by overwrite or deletion. A relevant incident extract may be kept longer for an active complaint, access request, insurance matter or legal requirement, with access limited and the need reviewed. The actual recording and deletion settings must be verified before CCTV starts.
You can ask for footage containing your personal information. Contact us promptly with the date, approximate time and location so we can identify and preserve relevant footage where available.
9. Voice notes and AI visit reports
Staff can deliberately record or upload a short note about one dog’s visit, or type rough notes, and ask OpenAI to suggest readable report text. This is not continuous audio monitoring. Staff compare the transcript or source notes, correct the report and explicitly approve it before it appears in the owner’s account. Email notifications are recorded locally in this preview, not delivered.
Only the selected clip or typed note is sent to OpenAI; we do not automatically include the customer account, contact details, dog profile or care history. Staff must leave out contact details, access codes and unrelated personal information. Recording does not send anything until staff choose to prepare a suggestion.
Waggle Room does not save raw audio to its database or files. The clip remains temporarily in the recording browser until it is discarded or the editor closes. Source text and suggestions are held in server memory for up to ten minutes to prevent duplicate requests, then discarded. The report wording staff explicitly save is retained as a care record. An uploaded original remains wherever staff stored it on their device.
OpenAI processes the submitted content under its API data controls. We request that rewrite responses are not stored as application state; this does not guarantee zero provider retention. Provider processing locations, applicable retention and account data-use settings must be verified before real customer notes are used. The current local build is for rehearsals with fictional notes.
AI will not decide admission, diagnose illness, invent medication instructions or publish reports without staff review. The final privacy notice must explain the actual data processing before real customer information is used with the feature.
To finalise: OpenAI is the connected provider when server credentials are configured. Confirm the live privacy notice, overseas-processing safeguards and provider account settings before using real customer notes. See https://developers.openai.com/api/docs/guides/your-data for provider data controls.
10. How long information is kept
We keep personal information only while needed for its lawful purpose. Different records need different periods: active care and contact records support the relationship; agreement, incident and complaint records may be needed to resolve issues; tax and accounting records generally need to be kept for at least seven tax years.
The planned normal CCTV period is 14 days, with limited preservation as described above. Unneeded enquiries, outdated care records, access codes and recordings should be deleted or de-identified when no longer needed. Financial retention requirements do not justify keeping every care note or entry code for seven years.
Before launch we must adopt and implement a schedule for enquiries, inactive accounts, dog documents, care/incident records, voice recordings and backups. Automatic deletion for these categories is not implemented in the local preview. Closing an account does not require us to erase records we lawfully need to retain; we will explain what remains and why.
To finalise: Aimee and Ash must confirm the remaining retention periods and deletion process with their accountant, insurer and privacy adviser before live collection.
11. Access, correction and complaints
Email info@waggleroom.co.nz to ask for access to or correction of your personal information, change contact details or discuss deletion. We may need to verify your identity. We will respond to access/correction requests as soon as reasonably practicable and normally within 20 working days, or explain a lawful extension. A decision to grant access and the actual provision of information may occur at different times.
If we cannot make a requested correction, you may ask for a statement of the correction sought to be attached to the information. Access may require protecting other people’s information or applying a lawful withholding ground, which we will explain where required.
Raise a privacy concern with Aimee or Ash first. You can also contact the Office of the Privacy Commissioner at privacy.org.nz about your rights or a complaint.
12. Privacy incidents and updates
If a privacy incident occurs, we will work to contain it, assess the risk and meet applicable notification duties. Where a breach has caused or is likely to cause serious harm, we will notify the Privacy Commissioner and affected people as soon as practicable, subject to lawful exceptions.
The review date and version identify this notice. We will explain material changes, especially new uses or providers, before they affect you where required. A Privacy Policy is an explanation of our practices; it is not a request to waive your privacy rights or an all-purpose consent.
Prefer to talk it through?
Aimee and Ash can help explain the arrangements or provide a copy to read before you enrol.
Email the Waggle Room team ↗Document version: waggle-privacy-2026-09-28-v3
Back to top ↑