PRIVACY POLICY
Your information, handled properly.
Canterbury Hoist Services respects your privacy and is committed to protecting the personal information we collect and hold. This Privacy Policy explains how we collect, use, store, disclose and protect personal information in accordance with the New Zealand Privacy Act 2020.
EFFECTIVE DATE — 11 JUNE 2026
Who we are
Canterbury Hoist Services is operated by Rock Wren Limited T/A Canterbury Hoist Services. We provide installation, servicing, certification, inspection, maintenance and repair services for vehicle hoists and workshop equipment. In this policy, “we”, “us” and “our” refer to Rock Wren Limited.
Personal information we collect
We may collect personal information from customers, suppliers, contractors, employees, prospective employees and other people we deal with in the course of business. This may include:
- Name
- Business name
- Job title or role
- Email address
- Phone number
- Postal or physical address
- Billing and payment details
- Workshop or site address
- Equipment details linked to your business or premises
- Service, inspection, certification, maintenance and repair records
- Customer communication history
- Health and safety, site access, or contractor induction information
- Photos, notes, reports, forms, checklists and technician observations
- Information provided through our website, enquiry forms, emails, phone calls, quotes, invoices, or service bookings
How we collect personal information
We may collect personal information when you:
- Contact us by phone, email, website, social media, or in person
- Request a quote
- Book a service, repair, installation, inspection, or certification
- Purchase goods or services from us
- Provide supplier, contractor, or account details
- Complete a credit application, account form, or customer information form
- Interact with our website
- Provide information for health and safety, site access, compliance, or invoicing purposes
We may also collect information from third parties where appropriate, such as suppliers, contractors, credit reference agencies, debt collection agencies, publicly available sources, or another person within your business.
Use of ServiceM8 CRM and job management system
We use ServiceM8 as our customer relationship management, job management, scheduling, quoting, invoicing and service record system. Personal and business information may be entered, stored and managed in ServiceM8 so we can carry out our services efficiently and maintain accurate records. This may include:
- Customer and business contact details
- Site and workshop addresses
- Job booking information
- Quotes, invoices and payment details
- Equipment details
- Service, repair, installation, inspection and certification records
- Photos, notes, reports, forms, checklists and technician observations
- Communication history relating to jobs or customer accounts
We use this information to manage customer jobs, keep accurate service history, issue documentation, communicate with customers, and meet our legal, accounting, health and safety and business record obligations.
ServiceM8 is a third-party software provider. Information stored in ServiceM8 may be held using cloud-based systems, which may include storage or processing outside New Zealand. ServiceM8 states that data transferred between users and ServiceM8 is encrypted, and that data may be stored in multiple locations around the world, including the United States, Australia, Ireland, Singapore and Tokyo.
Access to ServiceM8 is limited to authorised users who need the information to perform their role.
Why we collect and use personal information
We may use personal information to:
- Provide quotes, products and services
- Install, service, inspect, certify, maintain and repair workshop equipment
- Keep accurate service, inspection, certification and maintenance records
- Manage customer accounts and billing
- Process payments and follow up overdue accounts
- Communicate with customers, suppliers, contractors and staff
- Order parts, arrange freight, or manage supplier relationships
- Enter, store and manage customer and job information in ServiceM8
- Meet our legal, tax, accounting, health and safety, insurance and compliance obligations
- Improve our services, systems and customer experience
- Respond to enquiries, complaints, or disputes
- Maintain business records
- Send service reminders, updates, or relevant business communications
Website information, cookies and analytics
When you visit our website, we may collect limited technical information, such as:
- IP address
- Browser type
- Device type
- Pages visited
- Date and time of visit
- How you interacted with our website
This website does not currently use third-party advertising or analytics cookies — only the cookies strictly necessary for the site to function. If we introduce cookies or analytics tools to understand website traffic, improve website performance, or make our website easier to use, we will update this policy.
You can disable cookies through your browser settings, although some website features may not work as intended.
Who we may share personal information with
We may share personal information where necessary with:
- Our employees, contractors and service providers
- CRM, job management, scheduling, quoting, invoicing and service record software providers, including ServiceM8
- Resend — which delivers the confirmation and notification emails triggered by enquiries and service requests made through this website
- Vercel — our website hosting provider, which processes requests made to this site
- Suppliers and freight providers
- IT, software, website, cloud storage and administration providers
- Accountants, bookkeepers, banks, insurers and professional advisers
- Debt collection or credit reference agencies, where required
- Government agencies, regulators, or law enforcement, where required by law
- Health and safety, compliance, or certification bodies, where relevant
- A purchaser or potential purchaser of our business, if applicable
We do not sell personal information.
Overseas storage or service providers
Some of our service providers may store or process information overseas, including cloud-based software, email, accounting, website, job management, CRM, or data storage providers. This includes ServiceM8, which may store or process business and customer information using overseas cloud-based infrastructure.
Where we use overseas service providers, we take reasonable steps to ensure personal information is handled securely and only used for legitimate business purposes.
How we protect personal information
We take reasonable steps to protect personal information from loss, misuse, unauthorised access, disclosure, alteration, or destruction. This may include:
- Password-protected systems
- Restricted access to business records
- Secure digital storage where practical
- Authorised-user access to ServiceM8
- Staff and contractor confidentiality expectations
- Secure disposal of information no longer required
- Keeping business systems and records reasonably up to date
How long we keep personal information
We keep personal information for as long as reasonably necessary for the purpose it was collected, including for service history, equipment records, accounting, tax, legal, health and safety, insurance, warranty, compliance and business record purposes. When information is no longer required, we will take reasonable steps to securely delete, destroy, or anonymise it.
Accessing and correcting your personal information
You have the right to ask us what personal information we hold about you and to request correction if it is wrong, incomplete, or out of date. To request access or correction, please contact us using the details below. We may need to verify your identity before providing access or making changes.
Privacy breaches
If we become aware of a privacy breach, we will assess the situation and take appropriate steps to contain and manage it. If a privacy breach has caused, or is likely to cause, serious harm, New Zealand organisations must notify the Privacy Commissioner and affected people as soon as practicable. The Office of the Privacy Commissioner notes that notification should ideally be made within 72 hours of becoming aware of a notifiable breach.
Privacy Officer
Privacy enquiries can be directed to:
Complaints
If you have a concern about how we have handled your personal information, please contact us first so we can try to resolve the issue. If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner at privacy.org.nz or on 0800 803 909.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with a revised effective date, and the latest version is also available from us on request.