Privacy policy
PURPOSE
The NZ Super Rugby Clubs Online Store (“we”, “us”, “our”) is operated by Classic Sports Industries NZ Limited (CSI NZ) on behalf of the New Zealand Super Rugby Clubs.
We are committed to protecting the privacy and personal information of our customers. This Policy explains how we collect, use, store, disclose, and protect your personal data in accordance with the New Zealand Privacy Act 2020 and recognised information-security standards.
SCOPE
This Policy applies to all personal information collected from customers via:
- our online store
- customer accounts
- email communications
- competitions or promotions
- customer service interactions
- website usage and analytics
It covers both digital and physical records and applies to all CSI NZ personnel and authorised third-party processors acting on our behalf.
TYPES OF INFORMATION WE COLLECT
We only collect information necessary for our operations, including:
- Full name and contact details (email, phone number, postal address)
- Account login credentials (if you create an account)
- Order history, transaction details, and delivery information
- Payment method details (note: we do not store raw credit card numbers; tokenised data only where essential and permitted)
- Preferences, feedback, and communication history
- Customer service correspondence
-
Website usage data such as:
- cookies
- device/browser information
- IP address
- timestamps and pages visited
It covers both digital and physical records and applies to all CSI NZ personnel and authorised third-party processors acting on our behalf.
Why We Collect Your Information
We collect and use your personal information for purposes including:
- Processing and fulfilling orders
- Managing customer accounts and order communication
- Providing customer support and resolving enquiries
- Managing marketing and promotional activities (only where consent is provided)
- Improving website functionality, performance, and customer experience
- Meeting our legal and regulatory obligations
- Fraud prevention, security, and system integrity monitoring
STORAGE AND SECURITY OF YOUR DATA
We take reasonable steps to protect personal information from:
- misuse
- interference
- loss
- unauthorised access
- modification
- disclosure
Our security controls include:
- secure servers and encrypted databases
- password-protected systems
- role-based access controls
- anti-malware protection and regular monitoring
- routine system audits and access reviews
- secure disposal of records when they are no longer required
Payment Data:
All sensitive cardholder information is processed through PCI DSS-compliant payment gateways. We do not store raw credit card details. Tokenised payment data, where used, is encrypted and subject to strict access controls.
DISCLOSURE OF PERSONAL INFORMATION
We do not sell your personal information.
We may share your data with trusted third parties who assist us in operating the online store, including:
- delivery and courier companies
- payment processors
- IT and website support providers
- customer service partners
- regulatory bodies where required by law
Any third party receiving your data must comply with confidentiality, security, and contractual data-protection requirements.
DISCLOSURE TO NZ SUPER RUGBY CLUBS
We may share your personal information with the New Zealand Super Rugby Clubs for operational purposes, customer service, fulfilment support, and—where you have provided explicit marketing consent—for sending club-related updates, promotions, and communications.
OVERSEAS DISCLOSURE
Your personal information may be processed or stored by service providers located outside New Zealand (for example, in Australia or other jurisdictions).
We will only disclose your data overseas where:
- it is necessary to fulfil your order or provide services, or
- you have provided consent, and
- we have taken reasonable steps to ensure the overseas recipient complies with the New Zealand Privacy Act 2020 or provides comparable safeguards.
CUSTOMER RIGHTS AND ACCESS
You may request to:
- access the personal information we hold about you
- correct any inaccurate or outdated information
- request deletion of your personal information where legally permissible
- opt out of marketing communications at any time
Requests may be lodged by contacting us using the details in the Contact Us section.
We will acknowledge your request within 10 business days and respond in accordance with New Zealand privacy law.
DATA BREACHES
We maintain procedures for identifying and responding to data breaches.
If your personal information is involved in a breach that is likely to cause serious harm, we will:
- notify you
- notify the New Zealand Privacy Commissioner
- investigate, contain, and remediate the breach
- record all actions taken
Requests may be lodged by contacting us using the details in the Contact Us section.
We will acknowledge your request within 10 business days and respond in accordance with New Zealand privacy law.
CREDIT CARD AND SENSITIVE INFORMATION
We limit our collection and storage of sensitive information. Where financial information or other sensitive data is processed:
- encryption is applied
- strict access restrictions are enforced
- supplier due diligence is undertaken
- PCI DSS-compliant systems are used
If we ever store or process larger volumes of financial data, we will ensure full compliance with all relevant industry and legislative obligations.
POLICY UPDATES
This Policy may be updated periodically to reflect:
- changes in our legal obligations
- updates in operational practices
- improvements in our security standards
The latest version will be available on our website upon publication.
CONTACT US
For privacy enquiries, complaints, or to exercise your rights, please contact:
NZ Super Rugby Clubs Online Store – Retail Manager
Email: Online@shop.nzsuperrugbyclubs.co.nz
Complaints will be handled under our internal privacy complaints procedures and may be escalated to the New Zealand Privacy Commissioner if unresolved.