Privacy Policy

Last Updated: 28 July 2026
Effective Date: 28 April 2026
Applies to: Brhan website (www.brhan.io), Brhan iOS app, and Brhan Android app (collectively, the “Brhan Platform” or “Service”).

1. Who We Are

The Brhan Platform is operated by Brhan Enterprise Ltd (“Brhan”, “we”, “us”, or “our”), a company registered in New Zealand.

Registered office: Auckland, New Zealand
Email: [email protected] (privacy matters) · [email protected] (general)
Phone: +64 22 073 2188

For the purposes of the New Zealand Privacy Act 2020, the EU/UK GDPR, and the California Consumer Privacy Act, Brhan Enterprise Ltd is the data controller of the personal information processed through the Brhan Platform.

2. Scope of This Policy

This single policy covers all of the following:

  • The Brhan website at www.brhan.io and its subdomains;
  • The Brhan iOS app available on the Apple App Store;
  • The Brhan Android app available on the Google Play Store;
  • Any related services, customer support channels, and marketing communications.

By using the Brhan Platform, you acknowledge you have read and understood this policy. If you do not agree with how we handle your information, please do not use the Service.

3. Information We Collect

3.1 Information you provide directly

  • Account information: name, email address, phone number, password (hashed), profile photo, and date of birth (used for age-gating).
  • Buyer information: shipping address, billing address, order history, in-app messages, product reviews, ratings, returns and refund requests.
  • Seller information: business name, business registration number, store description, product listings, photos, pricing, payout bank details (collected and held by Stripe, not by Brhan), and tax-related information where required.
  • Seller verification (KYC): a copy of a valid government-issued driver’s licence or passport, business registration evidence where applicable, and any additional documents required to satisfy Stripe’s identity verification (Know-Your-Customer / Know-Your-Business obligations under anti-money-laundering law).
  • Communications: messages you send through the in-app chat between buyers and sellers, support tickets, and any correspondence with us.
  • User-generated content: product reviews, ratings, store photos, and other content you choose to publish on the Service.

3.2 Information collected automatically

  • Device information: device model, operating system and version, device language, time zone, mobile carrier, screen size, and an anonymous device identifier.
  • App diagnostics: app version, crash logs, and performance data, used to fix bugs and improve stability.
  • Usage data: screens viewed, features used, search queries, products viewed, items added to cart, and session duration, used to understand and improve the Service.
  • Approximate location: derived from IP address or device coarse location (with permission), used to show locally relevant listings, sellers, and shipping options. We do not collect precise GPS location.
  • Network information: IP address and approximate network location.
  • Cookies and similar technologies on the website (see Section 16).
  • Fraud-prevention signals: limited device fingerprint data and risk signals used to detect fraudulent accounts, payment fraud, and abuse (lawful basis: legitimate interest).

3.3 Information from third parties

  • Sign-in providers: if you sign in with Google or Apple, we receive your name, email address, and a unique identifier from that provider.
  • Payment processor: Stripe shares limited transaction status, payout status, and verification status with us. Stripe collects and processes full card and bank details directly, Brhan never receives or stores your full card number.
  • Communications providers: delivery and engagement metadata from email (Mailchimp), SMS/voice (Twilio), and WhatsApp Business messaging.

3.4 Sensitive information

The KYC documents (driver’s licence or passport) we collect from sellers contain sensitive identifiers. We treat these documents as confidential, use them solely for identity verification and regulatory compliance, store them with restricted access, and delete them in line with the retention schedule in Section 12.

We do not intentionally collect special categories of data such as race, religion, political views, sexual orientation, biometric data, or health information.

4. How We Use Your Information

PurposeExamples
Provide the ServiceCreate your account; show listings; allow buyers and sellers to transact; deliver in-app messages; process orders, refunds, and returns.
Verify identityVerify sellers using ID documents and business registration to comply with anti-money-laundering and consumer-protection law.
Process payments & payoutsCharge buyers, pay sellers via Stripe Connect, calculate platform fees, handle disputes and chargebacks.
Customer supportRespond to enquiries, resolve disputes between buyers and sellers, investigate complaints.
Safety, fraud and abuse preventionDetect and prevent fraud, account takeover, illegal listings, and policy violations.
Improve the ServiceDiagnose crashes, measure feature performance, analyse usage trends, A/B test improvements.
CommunicationsSend transactional notifications (order updates, password resets, verification codes); send marketing where you have opted in.
Legal & complianceMeet tax, anti-money-laundering, consumer-protection, and other legal obligations; respond to lawful requests.

For users in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6 of the GDPR:

  • Contract (Art. 6(1)(b)): to provide the Service you have signed up for, account creation, order processing, communications between buyers and sellers.
  • Legal obligation (Art. 6(1)(c)): to comply with anti-money-laundering, tax, consumer protection, and similar laws, including KYC verification of sellers.
  • Legitimate interests (Art. 6(1)(f)): to keep the Service secure, prevent fraud, debug and improve it, and run limited first-party analytics. We balance these interests against your rights and freedoms.
  • Consent (Art. 6(1)(a)): for marketing emails, push notifications, non-essential cookies, and any optional data processing. You can withdraw consent at any time.

6. How We Share Your Information

We share personal information only as described below. We do not sell personal information.

  • With other users of the Service: when you place an order, the seller receives your name, shipping address, contact number, and order details so they can fulfil it. Buyers see the seller’s store name, public listings, and reviews. In-app chat messages are visible to the participants.
  • With our service providers: Firebase (Google), Stripe, Mailchimp, Twilio, WhatsApp Business (Meta Platforms Ireland), Google Maps, Google Analytics, Apple (Sign in with Apple, APNs), and our cloud infrastructure provider (Google Cloud Platform). Each provider is bound by contractual confidentiality and data-protection obligations.
  • For legal reasons: to comply with valid legal process, court orders, or law-enforcement requests; to enforce our Terms of Service; or to protect the rights, safety, or property of Brhan, our users, or others.
  • In a corporate transaction: if Brhan is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred to the successor entity, subject to this policy.
  • With your consent: for any other purpose disclosed at the time of collection.

7. Third-Party Services and SDKs

The Brhan Platform integrates the following third-party services. Each operates under its own privacy policy:

ProviderPurposeData sharedPrivacy policy
Firebase Authentication (Google)Account sign-inEmail, phone, OAuth tokens, device identifierslink
Firebase Crashlytics (Google)Crash reportingCrash logs, device model, OS version, app versionlink
Firebase Analytics / Google AnalyticsProduct analyticsUsage events, screens, anonymous identifierslink
PostHogProduct analyticsUsage events, pages and screens viewed, anonymous identifier, account identifier, device type, app version, approximate countrylink
Firebase Cloud MessagingPush notificationsDevice push token, message metadatalink
Apple Push Notification service (APNs)iOS push notificationsDevice token, message metadatalink
Sign in with AppleiOS sign-in optionName, relayed email, opaque user IDlink
Google Sign-InSign-in optionName, email, profile photo, Google IDlink
Stripe / Stripe ConnectPayments & seller payoutsCard details (collected by Stripe directly), bank details, KYC documents, transaction datalink
Google Cloud PlatformApplication hosting and storageAll Service data (encrypted at rest)link
Google MapsMaps and location displayApproximate location, IP addresslink
Mailchimp (Intuit)Marketing & transactional emailName, email, engagement metricslink
TwilioSMS & voice (verification, notifications)Phone number, message metadatalink
WhatsApp Business (Meta)Customer support messagingPhone number, message contentlink

We do not use third-party advertising SDKs. The Brhan apps do not include Meta (Facebook) Ads SDK, Google AdMob, or any other advertising network. We do not use the Apple Advertising Identifier (IDFA) or the Google Advertising ID for tracking.

8. Mobile App Permissions (iOS & Android)

The Brhan apps request only the permissions needed to deliver the features you choose to use. You can grant or revoke any permission in your device’s system settings at any time.

PermissionWhy we askRequired?
CameraTake photos of products (sellers) and capture KYC document imagesOptional, only when uploading photos or completing seller verification
Photos / Photo LibraryChoose existing images for product listings or your profileOptional
Approximate (coarse) locationShow local listings, sellers, and shipping optionsOptional, service works without it
Push notificationsOrder updates, chat messages, and important account alertsOptional
Biometric authentication (Face ID / Touch ID / Android biometric)Optional faster sign-in; biometric data never leaves your deviceOptional

The Brhan apps do not request: precise GPS location, microphone access, contacts, calendar, SMS reading, call logs, Bluetooth, or background location.

9. Marketplace Specifics: Buyers, Sellers & Verification

9.1 Dual-role accounts

A single Brhan account may act as both a buyer and a seller. The information visible to other users depends on the role you are acting in for any given transaction.

9.2 Seller identity verification (KYC)

To list and sell on the Brhan Platform, sellers must complete identity verification. We collect:

  • A clear copy of a valid government-issued driver’s licence or passport;
  • Business registration evidence where the seller is operating as a business;
  • Any additional information required by Stripe Connect or applicable law (date of birth, residential address, taxpayer identifier).

We use these documents to satisfy our anti-money-laundering, counter-terrorism-financing, consumer-protection, and tax obligations. Verification is performed jointly with Stripe Identity. Documents are stored encrypted, with strictly limited internal access, and are deleted in accordance with the retention schedule in Section 12.

9.3 Information shared between buyers and sellers

To complete a transaction, sellers receive the buyer’s name, shipping address, contact details, and order details. Buyers receive the seller’s public store name, listings, and ratings. We require sellers (by contract) to use buyer information solely to fulfil orders and meet legal obligations, and not for unrelated marketing.

9.4 In-app chat

Buyers and sellers can communicate through Brhan’s in-app chat. Messages are stored on our servers so users can refer back to them, and may be reviewed by Brhan in cases of fraud, abuse, dispute resolution, or legal obligation.

9.5 Public reviews

Reviews and ratings you publish are visible to all users of the Service and are associated with your display name. Treat them as public.

10. Payments and Stripe Connect

All payments and seller payouts are processed by Stripe Payments Europe Ltd and its affiliates (“Stripe”) through Stripe Connect. Stripe acts as an independent data controller of payment data.

  • Card numbers, CVCs, and bank account numbers are entered directly into Stripe-hosted forms or Stripe SDK fields. Brhan never sees or stores your full card or bank account details.
  • Brhan receives only transaction status, last-four digits, brand, and high-level payout/verification status from Stripe.
  • Stripe’s processing is governed by the Stripe Privacy Policy and the Stripe Connected Account Agreement.

11. International Data Transfers

Brhan is incorporated in New Zealand. Our servers and databases are hosted on Google Cloud Platform in the United States. This means personal information collected from users anywhere in the world, including New Zealand, Australia, the European Economic Area, the United Kingdom, and elsewhere, is transferred to and stored in the United States.

For users in the EEA and the UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) with our processors, together with supplementary technical measures (encryption in transit and at rest, restricted access controls), to provide an adequate level of protection.

For New Zealand users, Information Privacy Principle 12 of the Privacy Act 2020 applies. Brhan’s contractual arrangements with overseas providers require comparable safeguards to the New Zealand Privacy Act.

You may request a copy of the relevant transfer mechanism by emailing [email protected].

12. Data Retention

CategoryRetention
Active account informationFor as long as your account is active.
After account deletion (general)Up to 30 days, after which we delete or anonymise. Backups are purged within a further 90 days.
Transaction records (orders, invoices)Up to 7 years from the transaction date, to meet New Zealand Inland Revenue and other tax-record obligations.
KYC documents (sellers)For the duration of your seller relationship and a further 7 years, in line with anti-money-laundering record-keeping requirements.
Customer support ticketsUp to 2 years.
Crash and diagnostic logsUp to 90 days.
Marketing engagement dataUntil you unsubscribe, plus 24 months for suppression.

13. Security

We use industry-standard safeguards to protect your information, including:

  • TLS 1.2+ encryption for data in transit;
  • Encryption at rest for databases, file storage, and backups;
  • Role-based access controls; least-privilege principles for staff;
  • Multi-factor authentication on internal admin tools;
  • Continuous logging and anomaly monitoring;
  • Regular vulnerability scans and security reviews of dependencies.

No system is perfectly secure. If we ever experience a data breach that meets the notification threshold under the New Zealand Privacy Act 2020, GDPR, or other applicable law, we will notify the Office of the Privacy Commissioner (or other relevant regulator) and affected individuals as required.

14. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights:

  • Access: request a copy of the personal information we hold about you.
  • Correction: ask us to correct information that is inaccurate or incomplete.
  • Deletion: ask us to delete your information, subject to legal retention obligations.
  • Portability: receive your information in a structured, machine-readable format (EEA/UK).
  • Object / restrict: object to processing based on legitimate interests, or ask us to restrict processing (EEA/UK).
  • Withdraw consent: withdraw any consent you have previously given (does not affect prior lawful processing).
  • Lodge a complaint: lodge a complaint with your local supervisory authority, for example, the NZ Office of the Privacy Commissioner (privacy.org.nz), the UK ICO (ico.org.uk), or your EU member-state authority.

To exercise any of these rights, email [email protected]. We will respond within 30 days (extendable by a further 30 days for complex requests) and may need to verify your identity before acting.

14.1 How to delete your account

You can delete your Brhan account at any time directly inside the Brhan mobile app:

  1. Open the Brhan app and sign in.
  2. Tap My profile from your account tab.
  3. Scroll to the Danger zone section and tap Delete my account.
  4. Confirm the deletion when prompted. The action cannot be undone.

If you can’t access the app, for example, you signed up only through the website, or you’ve already uninstalled the app, email [email protected] with the subject line “Delete my account” from the email address registered to your account. We will process the deletion within 7 days.

What gets removed: your name, email, phone number, profile photo, saved addresses, saved cards (which were already only stored as Stripe references on our side), and any other personal identifiers visible on your account.

What is retained: historical orders, invoices, refund records, and KYC documents (for sellers) are kept in de-personalised form for the periods set out in Section 12 above, because New Zealand tax law and anti-money-laundering legislation require us to keep them. After deletion these records are no longer linked to a personal profile and cannot be opened from the app.

15. Children’s Privacy

The Brhan Platform is intended for users aged 16 and over. We do not knowingly collect personal information from anyone under 13 years of age, and we do not direct the Service at children. Users between 13 and 15 must have a parent or legal guardian’s consent to use the Service.

If you believe a child has provided us with personal information without proper consent, please contact [email protected] and we will delete it promptly.

16. Cookies and Similar Technologies

The Brhan website uses cookies and similar technologies in three categories:

  • Strictly necessary: required to log you in, keep your session, and remember your cart. These cannot be turned off.
  • Analytics: Google Analytics / Firebase Analytics and PostHog, which measure how the site is used so we can improve it. These set a first-party identifier (brhanAnonymousId) that lets us recognise the same browser across visits without knowing who you are. If you sign in, that identifier is linked to your account so we can see the journey as one person rather than two strangers. These cookies are set only after you accept analytics cookies; if you decline, no analytics identifier is created and no usage events are sent.
  • Functional: remember preferences such as language and locale.

The Brhan apps do not use browser cookies; they use equivalent anonymous device identifiers and push tokens for the same purposes. Analytics in the apps is not governed by the website cookie banner: you can stop it by disabling app tracking in your device settings, or by asking us at [email protected].

Where required by law, we will request your consent through a cookie banner on first visit, and you can change your preferences at any time via the cookie settings link in the website footer.

17. Marketing & Communications

  • Transactional messages (order confirmations, password resets, security alerts) are sent on the basis of contract and cannot be turned off while you have an active account.
  • Marketing emails are sent only with your opt-in consent. Every marketing email contains an unsubscribe link, or you can update preferences in your account settings.
  • Push notifications can be enabled or disabled at any time in your device settings.
  • SMS marketing: we do not send marketing SMS. Twilio is used only for verification codes and operational alerts.

18. AI and Automated Decision-Making

Brhan does not use your personal information to train third-party AI models. We do not subject users to fully automated decisions that produce legal or similarly significant effects without human review. Limited automated risk-scoring is used to flag potentially fraudulent activity; flagged accounts are reviewed by a human before any restrictive action is taken.

19. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act, as amended by the CPRA:

  • The right to know what personal information we collect, use, and disclose;
  • The right to delete personal information we hold about you;
  • The right to correct inaccurate personal information;
  • The right to opt out of the sale or sharing of personal information, note that Brhan does not sell or share personal information as those terms are defined under the CPRA;
  • The right to limit use of sensitive personal information;
  • The right not to be discriminated against for exercising your rights.

To exercise these rights, email [email protected]. You may use an authorised agent.

20. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will notify you by email and/or in-app notice at least 14 days before the changes take effect, and update the “Last Updated” date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

21. Contact Us

If you have questions, complaints, or requests about this policy or our handling of your personal information, please contact:

Brhan Enterprise Ltd, Privacy Team
Email: [email protected]
General: [email protected]
Phone: +64 22 073 2188
Auckland, New Zealand

This policy is governed by the laws of New Zealand. If you are a resident of the EEA, the United Kingdom, California, or another jurisdiction with mandatory privacy law, applicable mandatory consumer protections continue to apply.

© 2026 Brhan Enterprise Ltd. All rights reserved.