TheTinScan to give or tip

Data Deletion Notice

Version LAUNCH-2026-09-13-R3 — takes effect 13 September 2026 · How to delete your data from TheTin — including accounts created by signing in with Google or Microsoft.

This Notice applies to every TheTin account, regardless of sign-in method. Every account receives the same deletion and restoration process described below.

Who is responsible

NZ CORNERSTONE LIMITED, a New Zealand company, operates TheTin and is responsible for the account data covered by this Notice. Email Support (support@thetin.nz) for deletion and other requests.

If you have a TheTin account

Deleting your account deletes your data — all sign-in methods included. It's self-serve:

  1. Sign in at thetin.nz — with your email/password or the Google / Microsoft sign-in you used.
  2. Open your profile and choose Delete account.
  3. Confirm. Your account locks immediately, you are signed out, and we email you a confirmation with the deletion deadline and a link to ordinary sign-in.
  4. You have 7 days to change your mind. Sign in normally with the account's existing email/password or Google / Microsoft sign-in. You’ll see a confirmation to restore the account. Click Restore my account and the account is restored.
  5. Deletion runs as part of our daily maintenance job, so it happens at least 7 days after you confirm and may take up to a further day — never sooner. Once it runs it is permanent: your account, profile, pages, images, tips, support data, authentication tokens, and application event history are erased from our active application databases and object storage.

A few narrow records may survive deletion, explained in the privacy policy: financial ledger records of payment events, including pending or failed states (kept for record-keeping; removed from our live database only after our operator has archived a batch and acknowledged it; that archive is ciphertext we encrypt ourselves and may rest outside New Zealand, while plaintext records do not leave New Zealand — we do not delete these rows on a calendar anniversary); your page addresses (kept reserved permanently as address text only, never released or given to another account, whether or not the page ever received a payment); and limited technical records for payment integrity and abuse prevention.

Your linked Stripe account(s) are yours and are not deleted by TheTin. Disconnecting Stripe does not free them for another TheTin login. Once linked, they stay with this TheTin account. During the 7-day grace window every Stripe account still linked to this account continues to block a new connection elsewhere. After the purge deadline every remaining linked Stripe account is disconnected from TheTin; money already paid stays in those Stripe accounts. See the Terms of Use.

Short-lived operational and security logs are different from those active account records. Account purge cannot selectively delete an already-written redacted line. It may remain for the balance of Cloudflare Workers Logs' 3-day retention or Grafana Cloud's 14-day retention in its Australia region, then expires under the processor's retention schedule. Such lines may carry internal pseudonymous identifiers, but payer identity, account contact/profile content, full URLs, and passwords, tokens or other secrets are prohibited. We export or archive neither of these two log stores beyond that automatic expiry.

Aggregate service statistics are separate again, and are not account data. We also keep overall counts and timings about how the service is performing — such as how many payments happened in a period or how long a checkout took — never about any one person, page, or payment — in a Cloudflare Workers Analytics Engine dataset for up to 3 months, after which our operator may pull a copy to their own equipment in New Zealand for longer. Because this dataset cannot hold a name, page address, or any account or payment identifier, there is nothing in it for account deletion to remove. See the Privacy Notice for how this dataset works.

If you signed in with Google or Microsoft

Signing in with those providers creates an ordinary TheTin account — so the deletion steps above delete the same active account data, regardless of how you signed in. Removing TheTin in your provider's own settings stops TheTin's future access to your provider profile, but doesn't delete your TheTin account — use the steps above for that.

If you gave a tip or donation (no account)

You have no TheTin account to delete, and your card details go directly to Stripe — they never reach us.

We do hold limited contact details about you: the name and email address Stripe collected for your receipt. We keep them against that payment so the person or organisation you gave to can see who gave — otherwise every gift arrives from a stranger. They are shown to that recipient in their own dashboard and nowhere else, never in a payment alert, and never copied into the long-term financial records that outlive an account. We don't build a profile from them, we don't email you, and we never sell or share them.

If you choose to leave one optional plain-text message after we verify a successful payment, we save the first message once as pending, then return you to TheTin's home page; later attempts through that payment cannot replace it. Our automated moderation job runs every five minutes and processes a limited queue, so approval is not guaranteed within five minutes. Until approval, the recipient sees only “Message to be moderated” in authenticated payment history. Approved text is shown only to that recipient there. Rejected text, and text that moderation cannot approve after limited retries, is removed and never shown. We never include payer messages in notifications, operational or security logs, or the long-term financial ledger.

We also keep the payment record itself: amount, currency, TheTin fee, time, recipient page, and Stripe transaction identifiers. See the privacy policy for exactly what a payment records.

Your name, email, and any optional payer message are erased automatically when that recipient's account is purged. To have them removed sooner, email Support (support@thetin.nz) — tell us the recipient's page and the approximate date and amount so we can find the right payment. Deleting our copy does not delete Stripe's own records, which Stripe keeps under its own policy.

After we remove a payer message, a small marker stays with the payment until the recipient's account is purged. It holds none of the message and is not shown to the recipient; it exists only to stop the same payment from being used to submit a replacement message.

Need help?

Email Support (support@thetin.nz) and we'll help — including verifying and completing a deletion for you if you can't sign in.

TheTin · FAQ · Terms · Privacy · Support