Privacy Policy
Last updated: June 2026
Elkopay Limited (“Elkopay”, “we”, “us”, “our”) is committed to protecting personal information and complying with the New Zealand Privacy Act 2020 and the Information Privacy Principles. This policy explains what personal information we collect, how we use and disclose it, and the rights available to you.
Elkopay enables fitness businesses — gyms, studios, coaches and personal trainers (our “Merchants”) — to request and collect payments from their own customers (“Customers”) using licensed open-banking provider Blink Pay NZ Limited (“BlinkPay”).
1. The information we collect
From Merchants: name, email address, login credentials (passwords are managed and hashed by our authentication provider — we never see them in plain text), business name, and the payment volume processed through Elkopay.
From Customers (on a Merchant's behalf): first and last name, email address, optional phone number, and payment records (amounts, due dates, status, and the consent identifiers issued by BlinkPay).
We never collect, see or store your bank login or account credentials. All payment authorisation happens directly between the Customer and their bank through BlinkPay, using the Customer's own banking app.
We use essential cookies only (for authentication and sessions) and limited operational logs to secure and diagnose the service. We do not use tracking or advertising cookies.
2. How we use your information
- To operate, provide and improve the Elkopay platform.
- To initiate and process payment requests and consents through BlinkPay.
- To send account, payment and service notifications.
- To meet our legal, regulatory and contractual obligations, including record-keeping and anti-money-laundering requirements.
We do not sell personal information, and we do not use it for advertising. We do not use data retrieved for a Merchant for our own purposes unless the relevant Customer has given explicit, informed consent.
3. Open banking and disclosure to BlinkPay
To request or collect a payment, we disclose certain personal information (such as a Customer's name and the payment details) to BlinkPay so the payment consent can be created and authorised by the Customer's bank. This transfer is a disclosure under the Privacy Act 2020, and Elkopay and BlinkPay each act as independent parties (not as agents of one another) in respect of that information. By using Elkopay, you are informed that your personal information will be disclosed to BlinkPay for this purpose. BlinkPay handles that information under its own privacy policy and security controls.
BlinkPay is certified to ISO/IEC 27001:2022 (information security management) and does not hold customers' personally identifiable information for its own purposes — it processes information solely to facilitate payments between you, the Merchant and the bank. BlinkPay never sees or stores your bank login credentials.
4. Other parties we share information with
We use a small number of trusted providers, each bound to handle personal information securely and only as we specify:
| BlinkPay | Open-banking payment initiation and consent processing (New Zealand). |
| Supabase | Database and authentication. Data is stored in the Asia-Pacific (Mumbai, India) region. |
| Vercel | Application hosting and content delivery. |
| Loops | Sending transactional and account emails on our behalf. |
We may also disclose personal information where required or permitted by law.
5. Storage and overseas location
Your information is stored securely using Supabase infrastructure located in the Asia-Pacific (Mumbai) region, which is outside New Zealand. We take reasonable steps to ensure any overseas party holds the information subject to protections comparable to those required under the Privacy Act 2020 (Information Privacy Principle 12).
6. How we keep your information secure
- Encryption of stored data at rest (AES-256) and data in transit (TLS 1.2 or higher).
- Database-level access controls so each Merchant can only access their own data.
- Multi-factor authentication on administrative access to our infrastructure.
- Secure management of API keys and secrets — never stored in our source code.
7. How long we keep your information
We keep personal information only for as long as necessary for the purposes above, or as required by law or contract. Records of payment consents and transactions are retained for a minimum of seven (7) years. Full details are in our Data Retention Policy, available on request.
8. Privacy breaches
If a privacy breach occurs that is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the affected individuals as soon as practicable, in accordance with the Privacy Act 2020, and notify BlinkPay where the breach involves the BlinkPay platform.
9. Your rights
Under the Privacy Act 2020 you have the right to request access to, and correction of, the personal information we hold about you. Customers should generally contact their Merchant first; we will assist and transfer requests to the appropriate party where needed. To exercise these rights, contact us at support@elkopay.com.
10. Complaints
If you have a concern about how we have handled your personal information, contact us at support@elkopay.com and we will respond in line with our Complaints Procedure. If you are not satisfied, you may complain to the Office of the Privacy Commissioner (privacy.org.nz; 0800 803 909).
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to registered Merchants and reflected on this page. Continued use of Elkopay after changes take effect constitutes acceptance of the updated policy.
12. Contact
Elkopay Limited (company number 9422628; NZBN 9429053618283), 29b Collins Road, Richmond 7020, New Zealand. Privacy contact: support@elkopay.com.