TheTinScan to give or tip

Privacy Notice

Version LAUNCH-2026-09-13-R3 — takes effect 13 September 2026 · NZ CORNERSTONE LIMITED, operator of TheTin (thetin.nz), New Zealand · Questions: Support

This Notice describes how TheTin handles personal information now. Access, correction, and deletion rights are not reduced because a new version is published. This is the same published version as the Terms of Use.

Privacy at a glance

We do not sell or rent personal information.

If you give, you need no TheTin account. TheTin never sees your card number. Stripe processes the payment. The recipient sees the name and email Stripe collects for your receipt — so the gift is not anonymous to them. Your name and email are the contact details we keep. We also retain limited transaction information needed to operate TheTin and maintain payment records (amount, currency, our fee, time, page, Stripe identifiers). Optional messages are shown only to that recipient after moderation.

If you receive, TheTin does not hold your money. Payments go through your Stripe account. We store what we need to run your account and pages, and the payment records for those pages. Optional Telegram or website alerts, if you turn them on, send payment details — never who gave.

  • Who this applies to
  • If you give
  • If you receive
  • What we collect
  • Payments and Stripe
  • Who receives information
  • Where it is processed
  • Cookies
  • Security
  • How long we keep it
  • Deleting an account
  • Optional alerts
  • Your rights
  • Privacy breaches
  • Changes

1. Who this notice applies to

NZ CORNERSTONE LIMITED, a New Zealand company, operates TheTin and is the New Zealand privacy agency that collects and holds the personal information described in this Notice. Email Support (support@thetin.nz) for privacy, access, correction, or deletion requests.

This Notice covers people who give (no TheTin account needed) and people who receive (account holders). The Terms of Use are the agreement for account holders. This Notice is part of that agreement by reference.

2. If you make a donation

Is my donation anonymous?

No — not to the recipient. When you pay, Stripe’s checkout collects your name and email for the receipt. TheTin shows those to the person or organisation you paid, in their signed-in dashboard, so they know who gave. That is a courtesy to them, not a mailing list.

  • The recipient can see your name and email.
  • If you leave an optional message, they can see it only after it is approved (see below). Until then they see “Message to be moderated”.
  • TheTin does not see or store your card number. Card and wallet details go to Stripe.
  • Your name, email, and message are not shown on the public page, in payment alerts, or to anyone except that recipient (and us, to run the service).
  • That recipient may be outside New Zealand, and the privacy law that applies to them may not match New Zealand’s.

We do not email you as a giver, we do not build a marketing profile from the gift, and we do not sell or share your contact details with anyone else. We never put your name, email, or message in a payment alert — those can appear on a lock screen or leave for a server we do not control.

When the recipient deletes their TheTin account, your name, email, and any message are erased with their data. They are never copied into our long-term financial records. You can also ask us to remove them sooner — see Your rights.

Optional message

After a verified successful payment you may leave one optional plain-text message. We save the first message once as pending, then return you to TheTin’s home page; later attempts through that payment cannot replace it. Automated moderation runs every five minutes on a limited queue, so approval is not guaranteed within five minutes. If rejected, or if moderation cannot approve it after limited retries, the text is removed and never shown. Messages never enter notifications, operational or security logs, or our long-term financial ledger.

What we keep about the payment

Your name and email are the contact details we keep. We also retain limited transaction information needed to operate TheTin and maintain payment records: amount, currency, our fee, time, which page received it, and Stripe’s transaction identifiers. Contact details are not the same as those transaction records.

3. If you receive donations

TheTin does not hold your funds. Payments are processed by Stripe on your connected Stripe account. We store what we need to run your account and pages, and the payment records for those pages.

You see a giver’s name and email in your dashboard. You must treat that as someone else’s personal information — not a mailing list. You may not sell it, add it to a marketing list, or pass it on. See the Terms of Use.

We collect:

  • Sign-in: your email; if you use a password, a one-way hash of it (never the password itself); if you sign in with Google or Microsoft, the provider’s account identifier. We request only basic profile and email from those providers.
  • Suggested country: when an account is first created, we suggest a country from where you are connecting — worked out by Cloudflare — so we can set the account up in the right place. You can correct it in your profile.
  • Profile: display name, full name, phone, address, and country.
  • Pages: page addresses, display names, customisation, and images you upload.
  • Stripe link: identifiers of Stripe accounts linked to you, which one is used for new payments, and whether that account can accept charges. Bank details, ID documents, and payout information live with Stripe, never with us. Each Stripe account can be linked to only one TheTin account. Pausing payments in TheTin does not free that Stripe account for another TheTin login. Disconnecting Stripe does not free it either. Once linked, it stays with that TheTin account. During the 7-day deletion window every linked Stripe account still blocks a new connection elsewhere. After purge we disconnect every remaining linked Stripe account from TheTin.
  • Activity records: sign-ins, page changes, and payment events, kept as an audit trail for support and abuse prevention.
  • Optional alerts: the Telegram identifier you link, or the web address and signing secret for your own server. See optional alerts.

Account emails come from noreply@thetin.nz: verification, welcome, password reset, deletion notices, Terms/Privacy updates, enforcement notices, and (if alerts are off) a daily payment summary. No marketing lists, and no newsletter.

4. What information we collect and why

Information Who it relates to Why we use it
Account email and sign-in identifiers Recipient Login, verification, and important account messages
Profile and page content Recipient Operate and display the collection page
Giver name and email Giver Show the recipient who gave; not a mailing list
Optional giver message Giver Deliver one private note to the recipient after moderation
Transaction information Giver and recipient Process, reconcile, and keep payment records (amount, currency, fee, time, page, Stripe identifiers)
Stripe account identifiers Recipient Connect payments to the right Stripe account
Telegram identifier or webhook URL Recipient, if enabled Send optional payment notifications
Security and operational data Users and visitors Protect the service, prevent abuse, diagnose failures

We never collect card numbers, bank account details, or government ID documents. We don’t use advertising or visitor-tracking analytics. We do keep aggregate operational statistics for service monitoring — counts and timings, never a person, page, or payment identifier.

Contact details (name, email, phone) are not the same as transaction records. A giver’s name and email are erased with the recipient’s account. Limited financial records of the payment itself may remain for books and disputes (see How long we keep information).

5. Payments and Stripe

TheTin operates the collection page and associated application services. Stripe processes the payment and holds the recipient’s Stripe account, bank details, and card data.

TheTin does not set Stripe’s processing fees, payout schedule, verification, or retention. Stripe’s privacy policy governs what Stripe holds.

TheTin’s own fee is taken on the charge as a platform fee. We keep records of that fee because we must keep books.

6. Who we share information with

We don’t sell or rent anyone’s data, ever. We use a small set of service providers to operate:

Provider Purpose What they may receive
Stripe Payment processing Payment and giver information required by Stripe, on the recipient’s Stripe account
Cloudflare Hosting, delivery, security, automated moderation of submitted text Information required to operate and protect the service; never bank or card data. Also short-lived operational logs.
Oracle Cloud Infrastructure Email Delivery (Sydney); Amazon SES in Sydney as a live fallback Account and service email Email address and the message we need to send
Grafana Labs Operational monitoring Limited redacted operational and security logs
Google or Microsoft Optional sign-in Information required for authentication if you use that provider
Telegram Optional payment alerts The alert itself, if you enable Telegram notifications
A server you nominate Optional website alerts The event information you asked us to send to that URL

We may also disclose information to authorities if the law genuinely requires it — and nothing more than it requires.

Google: privacy. Microsoft: privacy. Telegram: privacy.

7. International processing

TheTin is operated from New Zealand by NZ CORNERSTONE LIMITED, but the services we use are not all in New Zealand.

Provider Purpose Where it may be processed
Stripe Payments Stripe’s international systems
Cloudflare Hosting, security, logs Cloudflare’s global network
Oracle Email Delivery / Amazon SES Account email Sydney
Grafana Cloud Operational logs Australia region
Google / Microsoft Optional sign-in Those providers’ own locations
Telegram Optional alerts Telegram’s systems, if enabled
Your webhook Optional alerts Wherever the URL you give us is hosted

A giver’s name and email are shown to the recipient they paid, who may be in a country TheTin currently offers.

Financial-record archives we encrypt ourselves may rest outside New Zealand as ciphertext. Plaintext records do not leave New Zealand.

We use those providers only to run TheTin, protect the service, send account email, sign you in, and process payments.

8. Cookies and similar technologies

TheTin uses cookies and local browser storage only to run the service, protect accounts and payments, and remember basic preferences. We do not use advertising cookies and we do not use third-party analytics.

  • Session cookies keep recipients signed in.
  • Security and flow cookies protect sign-in, account, and Stripe Connect flows from tampering, replay, or cross-site request attacks.
  • Preference cookies remember basic display choices.
  • Turnstile and local security storage support bot and abuse protection.
  • Session storage may temporarily keep display preferences that live only in your browser, and is cleared when the browser session ends.

9. Security

We use Cloudflare security tools, including Turnstile where needed, to protect payments, sign-in, and page claims. Cloudflare may process technical request signals such as IP address, browser/device signals, and challenge results for that purpose.

We keep limited technical security records (such as hashed identifiers, timestamps, and failed-attempt counts) to detect card testing, bots, and repeated abuse. Short-lived rate-limit counters are deleted after 30 days. We do not use them for advertising or sell them.

Operational logs are limited to information needed for security, troubleshooting, and running the service. We take measures so those logs do not unnecessarily record personal or payment information: giver identity, giver messages, recipient contact details, card/bank/ID data, passwords, tokens, full URLs, and secrets are prohibited from that channel.

We screen public-facing names and text, and optional private giver messages, with automated moderation so the platform isn’t used for scams or hate.

10. How long we keep information

Account and profile information stays while the account is active. After you delete the account and the 7-day window ends, we erase it from our live systems (see Deleting your account).

Giver name, email, and optional message stay with the recipient’s account. They are erased when that account is purged, or sooner if you ask us to remove them from a payment (see user data deletion).

Transaction records (amount, currency, fee, time, page, Stripe identifiers, and the recipient email as it stood when the payment was recorded) are kept for books, disputes, and legal obligations. They are not the giver’s contact details.

Operational and security logs are kept only for a limited period needed for security and troubleshooting. Cloudflare’s log store retains them for 3 days. Grafana Cloud in Australia retains them for 14 days on our current plan. We do not export or archive those two log stores beyond that expiry. An already-written redacted line cannot be selectively deleted when you delete your account; it then expires under that schedule.

Abuse-prevention records may remain where needed to prevent duplicate processing, card testing, bots, and repeated abuse. They are limited technical records, not profile records. Rate-limit counters are deleted after 30 days.

Aggregate service statistics (counts and timings, never a person, page, or payment identifier) may be kept in Cloudflare Analytics Engine for up to 3 months. Our operator may then pull a copy of those aggregates to equipment in New Zealand. Because nothing in that dataset identifies anyone, there is no personal information in it for account deletion to remove.

Page addresses stay reserved forever as address text only, so a printed QR cannot later pay a stranger. See deletion below.

11. Deleting your account

You can delete your TheTin account yourself — see user data deletion for the steps.

  1. You request deletion from Profile. The account locks immediately.
  2. You have 7 days to change your mind. Sign in normally and you’ll see a confirmation. Click Restore my account. Re-registering the same email does not restore the account.
  3. Permanent deletion happens at least 7 days after you confirm, and may take up to a further day, never sooner.
  4. We then erase account, profile, pages, images, payment history on TheTin, support data, sessions, and event history from our live systems.

Some limited records may remain:

  • Financial ledger records of payment events, including pending or failed states: the account email as it stood when the payment was recorded, the page path, amount, currency, our fee, time, status, and Stripe’s transaction identifiers. We remove them from our live systems only after our operator has archived a batch and acknowledged it. The operator stores that archive as ciphertext we encrypt ourselves, in storage the operator administers; that ciphertext may rest outside New Zealand. Plaintext records do not leave New Zealand. We do not delete these records on a calendar anniversary.
  • Page addresses are kept reserved permanently as address text only — no account, profile, or ownership attached — so a printed QR cannot later point at a different person. A new account cannot take back an old page address. The email address can be used to sign up again from scratch.
  • Payment integrity and abuse-prevention records as above.
  • Short-lived operational logs already written, until they expire (3 or 14 days as above).

Your Stripe account is yours and is not deleted by TheTin. After the purge deadline every remaining linked Stripe account is disconnected from TheTin. See the Terms of Use.

12. Optional payment alerts

If you do not turn Telegram or website alerts on, we email your verified account address once a day with a short summary of any payment that day that had no instant alert — amounts and how many, never who gave. Nothing sends on a quiet day. Turning on Telegram or a website callback for those payments going forward is what stops the daily email, one channel at a time.

If you enable Telegram notifications, relevant payment-notification information is sent to Telegram so the notification can be delivered. The message then follows Telegram’s own privacy policy.

If you configure a website alert, relevant event information is sent to the URL you provide. You are responsible for ensuring that endpoint treats the information appropriately. Where that server is, and who can read it, is yours, not ours.

An alert carries the payment, never the person. It can include the amount, currency, TheTin fee, what reaches you where Stripe has told us, status, time, and which page. A refund alert can add the amount refunded in that step and the running total, as Stripe reports it. A giver’s name, email, and optional message are never included on either channel.

If a Telegram or website alert fails to deliver, we retry a few times; if it still hasn’t gone through, we switch that channel off and email your verified account address to say which one. We don’t include giver identity, the raw error a provider gave us, or your webhook address in that email. You can turn the channel back on from Notifications.

13. Your privacy rights

Under the New Zealand Privacy Act 2020 you can:

  • ask us for a copy of the personal information we hold about you
  • ask us to correct it
  • ask us to delete it where applicable
  • ask a privacy question

Email Support and we’ll respond. If you’re unhappy with how we handle it, you can complain to the NZ Office of the Privacy Commissioner (privacy.org.nz).

If you gave without a TheTin account, you may also ask us to remove your name, email, and any optional giver message from our copy of a payment. See user data deletion for what to send us so we can identify the correct payment.

14. Privacy breaches

If we suspect a privacy breach, we will assess it promptly, take reasonable steps to contain it, and work out who may be affected.

If a breach is likely to cause serious harm, we will notify affected people and the New Zealand Privacy Commissioner where the Privacy Act requires it.

If you think your account or data has been accessed without permission, email Support.

15. Changes to this Privacy Notice

If we change this policy, we’ll update this page and its version. We won’t quietly weaken it: any change that lets us collect more than described here will be announced to account holders by email first. Other updates use a new version; we email recipient account holders. If you keep using TheTin, you are agreeing to that version. If you do not agree, you can delete your account from Profile.

16. Contact us

Support (support@thetin.nz) — privacy, access, correction, deletion, and other requests. NZ CORNERSTONE LIMITED, New Zealand.

TheTin · FAQ · Terms · Privacy · Support