
Version LAUNCH-2026-09-13-R3 — takes effect 13 September 2026 · NZ CORNERSTONE LIMITED, operator of TheTin (thetin.nz), New Zealand · Questions: Support
We do not sell or rent personal information.
If you give, you need no TheTin account. TheTin never sees your card number. Stripe processes the payment. The recipient sees the name and email Stripe collects for your receipt — so the gift is not anonymous to them. Your name and email are the contact details we keep. We also retain limited transaction information needed to operate TheTin and maintain payment records (amount, currency, our fee, time, page, Stripe identifiers). Optional messages are shown only to that recipient after moderation.
If you receive, TheTin does not hold your money. Payments go through your Stripe account. We store what we need to run your account and pages, and the payment records for those pages. Optional Telegram or website alerts, if you turn them on, send payment details — never who gave.
NZ CORNERSTONE LIMITED, a New Zealand company, operates TheTin and is the New Zealand privacy agency that collects and holds the personal information described in this Notice. Email Support (support@thetin.nz) for privacy, access, correction, or deletion requests.
This Notice covers people who give (no TheTin account needed) and people who receive (account holders). The Terms of Use are the agreement for account holders. This Notice is part of that agreement by reference.
No — not to the recipient. When you pay, Stripe’s checkout collects your name and email for the receipt. TheTin shows those to the person or organisation you paid, in their signed-in dashboard, so they know who gave. That is a courtesy to them, not a mailing list.
We do not email you as a giver, we do not build a marketing profile from the gift, and we do not sell or share your contact details with anyone else. We never put your name, email, or message in a payment alert — those can appear on a lock screen or leave for a server we do not control.
When the recipient deletes their TheTin account, your name, email, and any message are erased with their data. They are never copied into our long-term financial records. You can also ask us to remove them sooner — see Your rights.
After a verified successful payment you may leave one optional plain-text message. We save the first message once as pending, then return you to TheTin’s home page; later attempts through that payment cannot replace it. Automated moderation runs every five minutes on a limited queue, so approval is not guaranteed within five minutes. If rejected, or if moderation cannot approve it after limited retries, the text is removed and never shown. Messages never enter notifications, operational or security logs, or our long-term financial ledger.
Your name and email are the contact details we keep. We also retain limited transaction information needed to operate TheTin and maintain payment records: amount, currency, our fee, time, which page received it, and Stripe’s transaction identifiers. Contact details are not the same as those transaction records.
TheTin does not hold your funds. Payments are processed by Stripe on your connected Stripe account. We store what we need to run your account and pages, and the payment records for those pages.
You see a giver’s name and email in your dashboard. You must treat that as someone else’s personal information — not a mailing list. You may not sell it, add it to a marketing list, or pass it on. See the Terms of Use.
We collect:
Account emails come from noreply@thetin.nz: verification, welcome, password reset, deletion notices, Terms/Privacy updates, enforcement notices, and (if alerts are off) a daily payment summary. No marketing lists, and no newsletter.
| Information | Who it relates to | Why we use it |
|---|---|---|
| Account email and sign-in identifiers | Recipient | Login, verification, and important account messages |
| Profile and page content | Recipient | Operate and display the collection page |
| Giver name and email | Giver | Show the recipient who gave; not a mailing list |
| Optional giver message | Giver | Deliver one private note to the recipient after moderation |
| Transaction information | Giver and recipient | Process, reconcile, and keep payment records (amount, currency, fee, time, page, Stripe identifiers) |
| Stripe account identifiers | Recipient | Connect payments to the right Stripe account |
| Telegram identifier or webhook URL | Recipient, if enabled | Send optional payment notifications |
| Security and operational data | Users and visitors | Protect the service, prevent abuse, diagnose failures |
We never collect card numbers, bank account details, or government ID documents. We don’t use advertising or visitor-tracking analytics. We do keep aggregate operational statistics for service monitoring — counts and timings, never a person, page, or payment identifier.
Contact details (name, email, phone) are not the same as transaction records. A giver’s name and email are erased with the recipient’s account. Limited financial records of the payment itself may remain for books and disputes (see How long we keep information).
TheTin operates the collection page and associated application services. Stripe processes the payment and holds the recipient’s Stripe account, bank details, and card data.
TheTin does not set Stripe’s processing fees, payout schedule, verification, or retention. Stripe’s privacy policy governs what Stripe holds.
TheTin’s own fee is taken on the charge as a platform fee. We keep records of that fee because we must keep books.
We don’t sell or rent anyone’s data, ever. We use a small set of service providers to operate:
| Provider | Purpose | What they may receive |
|---|---|---|
| Stripe | Payment processing | Payment and giver information required by Stripe, on the recipient’s Stripe account |
| Cloudflare | Hosting, delivery, security, automated moderation of submitted text | Information required to operate and protect the service; never bank or card data. Also short-lived operational logs. |
| Oracle Cloud Infrastructure Email Delivery (Sydney); Amazon SES in Sydney as a live fallback | Account and service email | Email address and the message we need to send |
| Grafana Labs | Operational monitoring | Limited redacted operational and security logs |
| Google or Microsoft | Optional sign-in | Information required for authentication if you use that provider |
| Telegram | Optional payment alerts | The alert itself, if you enable Telegram notifications |
| A server you nominate | Optional website alerts | The event information you asked us to send to that URL |
We may also disclose information to authorities if the law genuinely requires it — and nothing more than it requires.
TheTin is operated from New Zealand by NZ CORNERSTONE LIMITED, but the services we use are not all in New Zealand.
| Provider | Purpose | Where it may be processed |
|---|---|---|
| Stripe | Payments | Stripe’s international systems |
| Cloudflare | Hosting, security, logs | Cloudflare’s global network |
| Oracle Email Delivery / Amazon SES | Account email | Sydney |
| Grafana Cloud | Operational logs | Australia region |
| Google / Microsoft | Optional sign-in | Those providers’ own locations |
| Telegram | Optional alerts | Telegram’s systems, if enabled |
| Your webhook | Optional alerts | Wherever the URL you give us is hosted |
A giver’s name and email are shown to the recipient they paid, who may be in a country TheTin currently offers.
Financial-record archives we encrypt ourselves may rest outside New Zealand as ciphertext. Plaintext records do not leave New Zealand.
We use those providers only to run TheTin, protect the service, send account email, sign you in, and process payments.
TheTin uses cookies and local browser storage only to run the service, protect accounts and payments, and remember basic preferences. We do not use advertising cookies and we do not use third-party analytics.
We use Cloudflare security tools, including Turnstile where needed, to protect payments, sign-in, and page claims. Cloudflare may process technical request signals such as IP address, browser/device signals, and challenge results for that purpose.
We keep limited technical security records (such as hashed identifiers, timestamps, and failed-attempt counts) to detect card testing, bots, and repeated abuse. Short-lived rate-limit counters are deleted after 30 days. We do not use them for advertising or sell them.
Operational logs are limited to information needed for security, troubleshooting, and running the service. We take measures so those logs do not unnecessarily record personal or payment information: giver identity, giver messages, recipient contact details, card/bank/ID data, passwords, tokens, full URLs, and secrets are prohibited from that channel.
We screen public-facing names and text, and optional private giver messages, with automated moderation so the platform isn’t used for scams or hate.
Account and profile information stays while the account is active. After you delete the account and the 7-day window ends, we erase it from our live systems (see Deleting your account).
Giver name, email, and optional message stay with the recipient’s account. They are erased when that account is purged, or sooner if you ask us to remove them from a payment (see user data deletion).
Transaction records (amount, currency, fee, time, page, Stripe identifiers, and the recipient email as it stood when the payment was recorded) are kept for books, disputes, and legal obligations. They are not the giver’s contact details.
Operational and security logs are kept only for a limited period needed for security and troubleshooting. Cloudflare’s log store retains them for 3 days. Grafana Cloud in Australia retains them for 14 days on our current plan. We do not export or archive those two log stores beyond that expiry. An already-written redacted line cannot be selectively deleted when you delete your account; it then expires under that schedule.
Abuse-prevention records may remain where needed to prevent duplicate processing, card testing, bots, and repeated abuse. They are limited technical records, not profile records. Rate-limit counters are deleted after 30 days.
Aggregate service statistics (counts and timings, never a person, page, or payment identifier) may be kept in Cloudflare Analytics Engine for up to 3 months. Our operator may then pull a copy of those aggregates to equipment in New Zealand. Because nothing in that dataset identifies anyone, there is no personal information in it for account deletion to remove.
Page addresses stay reserved forever as address text only, so a printed QR cannot later pay a stranger. See deletion below.
You can delete your TheTin account yourself — see user data deletion for the steps.
Some limited records may remain:
Your Stripe account is yours and is not deleted by TheTin. After the purge deadline every remaining linked Stripe account is disconnected from TheTin. See the Terms of Use.
If you do not turn Telegram or website alerts on, we email your verified account address once a day with a short summary of any payment that day that had no instant alert — amounts and how many, never who gave. Nothing sends on a quiet day. Turning on Telegram or a website callback for those payments going forward is what stops the daily email, one channel at a time.
If you enable Telegram notifications, relevant payment-notification information is sent to Telegram so the notification can be delivered. The message then follows Telegram’s own privacy policy.
If you configure a website alert, relevant event information is sent to the URL you provide. You are responsible for ensuring that endpoint treats the information appropriately. Where that server is, and who can read it, is yours, not ours.
An alert carries the payment, never the person. It can include the amount, currency, TheTin fee, what reaches you where Stripe has told us, status, time, and which page. A refund alert can add the amount refunded in that step and the running total, as Stripe reports it. A giver’s name, email, and optional message are never included on either channel.
If a Telegram or website alert fails to deliver, we retry a few times; if it still hasn’t gone through, we switch that channel off and email your verified account address to say which one. We don’t include giver identity, the raw error a provider gave us, or your webhook address in that email. You can turn the channel back on from Notifications.
Under the New Zealand Privacy Act 2020 you can:
Email Support and we’ll respond. If you’re unhappy with how we handle it, you can complain to the NZ Office of the Privacy Commissioner (privacy.org.nz).
If you gave without a TheTin account, you may also ask us to remove your name, email, and any optional giver message from our copy of a payment. See user data deletion for what to send us so we can identify the correct payment.
If we suspect a privacy breach, we will assess it promptly, take reasonable steps to contain it, and work out who may be affected.
If a breach is likely to cause serious harm, we will notify affected people and the New Zealand Privacy Commissioner where the Privacy Act requires it.
If you think your account or data has been accessed without permission, email Support.
If we change this policy, we’ll update this page and its version. We won’t quietly weaken it: any change that lets us collect more than described here will be announced to account holders by email first. Other updates use a new version; we email recipient account holders. If you keep using TheTin, you are agreeing to that version. If you do not agree, you can delete your account from Profile.
Support (support@thetin.nz) — privacy, access, correction, deletion, and other requests. NZ CORNERSTONE LIMITED, New Zealand.