Privacy Policy

This policy explains what personal information we collect, why we collect it, who sees it and what you can do about it. It is written to meet the New Zealand Privacy Act 2020 and its 13 information privacy principles.

The short version

We collect what we need to take your order, deliver it and support it afterwards. We never sell your information. You can ask to see what we hold, ask us to correct it, and unsubscribe from email at any time.

Who we are

Securitylab is operated by Vimel Technology Pty Ltd, based in Sydney, Australia. For the purposes of the Privacy Act 2020 we are the agency responsible for the personal information collected through securitylab.co.nz.

What we collect

When you place an order

Your name, delivery address, billing address, email address and phone number, along with the details of what you ordered. We need all of it to get a parcel to the right door and to help you afterwards.

When you contact us

Whatever you choose to tell us in an email or a contact form, including any photos or video you send us about a fault.

When you browse the site

Standard web information: your IP address, the type of device and browser you are using, which pages you looked at, and how you arrived. This is collected by the Shopify platform the store runs on, and by any analytics we use, in order to keep the site working and to understand which pages are useful.

What we never see

Your full card number. Card payments are handled entirely by the payment provider on their own systems. We receive confirmation that a payment succeeded and the last few digits of the card, and nothing more.

Why we collect it

  • To process, pack, dispatch and track your order.
  • To answer your questions and handle warranty claims and returns.
  • To meet our tax and record keeping obligations.
  • To send you marketing email, but only if you have asked for it.
  • To improve the site and the buying guides.

We do not use your information for anything unrelated to the reason you gave it to us.

Who we share it with

Only the parties who need it to complete what you asked for:

ShopifyThe e-commerce platform this store runs on, which stores order and account data
Payment providersTo process your payment and to handle chargebacks and refunds
Couriers and postal servicesYour name, address and phone number, so they can deliver the parcel
Apps used by the storeSuch as wishlist and email tools, limited to what each one needs to function
Professional advisersAccountants and legal advisers, where required

We do not sell your personal information, and we do not trade or rent mailing lists. We will only disclose your information beyond the list above if you consent, if it is needed to prevent or lessen a serious threat to someone's life or health, or if the law requires it.

Information that goes overseas

You should know this, because most New Zealand privacy policies leave it out. We are an Australian company, and the Shopify platform stores data outside New Zealand. Some of the couriers, payment providers and software tools we use also operate offshore.

That means your personal information is held and processed outside New Zealand. Information privacy principle 12 of the Privacy Act 2020 governs this, and we only use providers that are subject to privacy safeguards comparable to those in New Zealand law.

How long we keep it

Order records are kept for seven years to meet tax and business record requirements. Email correspondence is kept while it is useful for supporting you and then deleted. Marketing contacts are kept until you unsubscribe. We do not keep personal information for longer than we need it.

Keeping it secure

The site runs over an encrypted connection. Access to order data is limited to the people who need it to do their job. Payment details are handled by the payment provider on their systems, not ours, which is deliberate: the safest way to protect card numbers is not to hold them.

Seeing and correcting what we hold

Under the Privacy Act 2020 you have the right to ask what personal information we hold about you, and to ask us to correct it if it is wrong.

Ask us and we will respond within 20 working days, which is the timeframe the Act sets. There is no charge. If we decline a request we will tell you why and explain your right to complain.

Marketing email

We only send marketing email to people who have asked for it. Every message carries a working unsubscribe link, as required by the Unsolicited Electronic Messages Act 2007, and unsubscribing takes effect immediately. Unsubscribing from marketing does not stop the emails you need about an order you have placed.

Cookies

The store uses cookies to keep your cart working, to keep you signed in, and to understand how the site is used. Blocking cookies in your browser will stop the shopping cart from working properly, which is a limitation of how online stores work rather than a choice we made.

If something goes wrong

If we have a privacy breach that has caused or is likely to cause serious harm, we are required to notify both you and the Office of the Privacy Commissioner. We will do so.

If you think we have mishandled your information, tell us first. That is not just a courtesy, it is the process: the Privacy Commissioner will not take a complaint until you have raised it with the agency involved. If we cannot resolve it, you can complain to the Office of the Privacy Commissioner.

Changes to this policy

If we change how we handle personal information we will update this page and change the date below. Material changes will be signalled clearly rather than slipped in.

Contact

For any privacy question, access request or correction request, get in touch and mark it for the attention of the privacy contact.

Last updated 25 August 2026.