Privacy policy

Toi Tauranga Art Gallery Privacy Policy

Effective Date: 11 November 2025

1. Introduction

Toi Tauranga Art Gallery ("we", "us", "our") is committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 2020. This Privacy Policy explains how we collect, use, disclose, and protect your information when you visit or make a purchase from our online store hosted on Shopify.

By using our website (the "Site"), you agree to the collection and use of information in accordance with this policy.

2. Who We Are

Toi Tauranga Art Gallery is located at 108 Willow Street, Tauranga, New Zealand.

For any privacy-related questions, you can contact our Privacy Officer at:
Email: hello@artgallery.org.nz
Postal Address: PO Box 13255, Tauranga, BOP, 3141, New Zealand
Phone (07) 578 7933

3. Personal Information We Collect

We collect personal information in order to provide our services and improve your experience. The types of personal information we may collect include:
- Contact details: name, email address, postal and billing address, phone number.
- Payment details: payment card information, billing and transaction information (processed securely by Shopify Payments or other providers — we do not store your full payment details).
- Account information: username, password, preferences, and settings.
- Transaction and order data: items purchased, returned, or added to your cart.
- Device and usage data: IP address, browser type, pages viewed, and time spent on the site.
- Communications: messages or feedback you send us.

We may also collect data automatically through cookies and similar technologies when you use our Site (see Section 6).

4. How We Use Your Information

We use your personal information for the following purposes:

To provide our services:
- Process your purchases, payments, and deliveries.
- Maintain your account and preferences.
- Respond to enquiries and provide customer support.

To communicate with you:
- Send you updates about exhibitions, events, and products.
- Manage subscriptions to newsletters and marketing emails (you may unsubscribe at any time).

To improve and personalise our services:
- Analyse site traffic and visitor interactions to enhance the user experience.
- Provide tailored recommendations and marketing.

To comply with legal obligations:
- Maintain records for tax and reporting purposes.
- Respond to lawful requests from regulators or authorities.

5. How We Disclose Your Information

We will never sell your personal information. We may share it with:
- Shopify and its service providers for hosting, analytics, and payment processing.
- Trusted third-party providers (e.g., shipping partners, IT support, marketing platforms) who process data on our behalf under confidentiality agreements.
- Regulators or authorities when legally required.
- Successor organisations in the event of a merger or transfer, subject to confidentiality.

You can read more about how Shopify handles your information at: https://www.shopify.com/legal/privacy

6. Cookies and Tracking

We use cookies and similar technologies to improve your browsing experience and analyse site performance. Cookies may be used to:
- Keep items in your shopping cart.
- Remember your preferences.
- Analyse website usage.
- Display personalised marketing content.

You can manage or disable cookies through your browser settings. Please note that some features of our Site may not function properly if cookies are disabled.

7. Data Security

We take reasonable steps to protect your personal information from unauthorised access, disclosure, alteration, or destruction.

Our store is hosted by Shopify, which provides PCI DSS–compliant security for all online payments. All data is transmitted using SSL encryption.

8. Data Retention

We retain your information only for as long as necessary to:
- Provide our services and complete transactions.
- Comply with legal, accounting, and reporting obligations.
- Resolve disputes and enforce agreements.

Transaction and financial data may be retained for up to 7 years as required by New Zealand tax laws.

9. Your Rights

Under the Privacy Act 2020, and where applicable international data protection laws (such as GDPR or CCPA), you may have the right to:
- Access the personal information we hold about you.
- Request correction of your personal information.
- Request deletion of your personal information.
- Request a copy of your data or data portability.
- Opt out of direct marketing communications.

You can make a request by contacting us at office@artgallery.org.nz.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner at https://www.privacy.org.nz/.

10. International Data Transfers

Because Shopify and some of our service providers are based overseas, your information may be transferred or stored outside New Zealand.

Where personal data is transferred internationally, we ensure that adequate safeguards are in place — for example, through Standard Contractual Clauses or equivalent protections.

11. Children's Data

Our Site is not intended for children under the age of 16. We do not knowingly collect personal information from minors. If you believe a child has provided us with their information, please contact us so we can delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons.

When updated, the revised policy will be posted on this page with a new 'Last Updated' date.
Significant changes will be communicated via our website or email where appropriate.

Last Updated: 11 November 2025

13. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

Toi Tauranga Art Gallery
Email: hello@artgallery.org.nz
Postal Address: PO Box 13255, Tauranga, BOP, 3141, New Zealand
Phone: (07) 578 7933