Privacy Policy
Updated 6 September 2026.
Tradevero runs this CRM and its portals at portal.tradevero.nz for its own staff, for the independent businesses that deliver cleaning services with Tradevero (providers), and for the customers whose sites those businesses look after (clients). This policy says what the system stores about you, why, who can see it, and how to ask about it.
What the system stores
- Your login. Name, email address, username, phone, position, role, and the times you sign in, with device type and IP address.
- Sales records. Business names, contact people, phone numbers, email addresses, addresses, notes, calls, callbacks, meetings, quotes and files that staff enter about leads and customers.
- Work records. Contracts, offers, commitments, payment receipts, job logs, checklists and the photos providers attach to a visit.
- Location, only when a provider checks in. A provider's position at the moment they check in to a job, so the visit can be confirmed. There is no background tracking.
- Messages. Chat messages, attachments and voice notes inside Tradevero Comms, and support tickets.
- Change history. Who changed what and when, kept so mistakes can be undone and disputes settled.
- Emails the system sends. Sign-in codes, welcome emails, reminders and the emails staff send to leads, with delivery status.
Why
To run Tradevero's business: win and serve customers, arrange and check cleaning work, pay providers, keep the records the law requires, and keep accounts secure. The system does not sell or rent personal information and does not use it for advertising.
Who sees it
- Tradevero staff see the records their role allows. Admins see everything in the business.
- Providers see their own profile, the contracts and sites assigned to them, their job logs and payments, and the chats they are in.
- Clients see their own sites, the providers assigned to them, visit records with photos, their contracts and their tickets.
- Service companies that host the system process data on Tradevero's behalf and under contract: Supabase (database and file storage), Vercel (the web app), Resend (email delivery) and, where staff connect it, Google (calendar and maps). None of them use the data for their own purposes.
Google services
A staff member can connect their Google Calendar. The system then uses Google user data only to create, update and remove the meetings booked in the CRM for that person, and to add a Google Meet link. It reads no other calendar entries and shares nothing with anyone else. The access token is stored encrypted and is deleted when the person disconnects, which they can do at any time from My profile or from their Google account settings. Tradevero's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Maps on lead pages come from Google Maps and load only the address shown on the page.
Security
Every sign-in with a password also needs a 6-digit code sent to your email. Data lives in Supabase in the Asia Pacific region behind row-level access rules, so each person only reaches what their role allows. The system backs itself up every 5 hours and keeps the newest three copies. All traffic is encrypted in transit.
How long
Records stay while Tradevero has a business or legal reason to keep them. Sign-in history and location check-ins are kept for a year. When a login is deleted, the personal profile goes with it and the work it did is handed to a Tradevero administrator.
Your rights
Under the Privacy Act 2020 (New Zealand) and the Privacy Act 1988 (Australia) you can ask what the system holds about you, ask for corrections, and ask for your login to be removed. Providers can also request account deletion from inside the portal. Contact the Tradevero team through your usual contact. Tradevero answers within 20 working days.
Changes
When this policy changes, the date at the top changes and the new version applies from then. If you keep using the system after that date, you accept the change.
See also the Terms of Service.