PRIVACY POLICY · VERSION 3.0 · 9 SEPTEMBER 2026
How Alpha & Omega Limited handles personal information through OmegaWebApps.
This policy is tailored to omegawebapps.com, Stripe checkout, support communications and the local-first design of the ten installed software products. It is drafted with regard to the New Zealand Privacy Act 2020, including the Information Privacy Principles and the newer IPP 3A indirect-collection transparency requirements.
1. Agency responsible
OmegaWebApps is operated by Alpha & Omega Limited, Auckland, New Zealand. For New Zealand Privacy Act purposes, Alpha & Omega Limited is the agency responsible for personal information it collects/holds through OmegaWebApps unless another notice identifies a different agency.
2. Scope
This policy covers personal information handled through omegawebapps.com, payment/order administration, digital delivery, email/contact/support, fraud/security processes, legal/compliance records and related business administration. Independent providers such as Stripe, hosting/email providers and social networks have their own privacy practices for information they control.
3. Information we may collect
- Name and contact details you provide.
- Purchase/order details, product purchased, payment status and transaction identifiers supplied by Stripe or related payment systems.
- Support information such as product/version, WordPress/PHP/server details, error messages, screenshots and logs you choose to provide.
- Communications with us.
- Ordinary hosting/security logs such as IP address, request URL, timestamp, user agent and error/security events where generated by the hosting environment.
- Any other information you voluntarily submit that is reasonably necessary to deal with your request.
We do not need your full payment-card number to fulfil a Stripe-hosted checkout and you should not send full card numbers, passwords or private keys through ordinary email/support channels.
4. How information is collected
Information may be collected directly when you contact us, purchase a product or seek support; automatically through ordinary website/server/security operation; or indirectly from service providers such as Stripe where needed to verify/fulfil a transaction. Where IPP 3A applies to indirect collection, we will take reasonable steps to provide the information required by that principle unless a lawful exception applies.
5. Purposes
We may use personal information to provide and verify purchases/delivery, answer enquiries, provide support, maintain accounting/tax/business records, prevent fraud/abuse, secure the website, investigate failures, comply with law, manage disputes and exercise or defend legal rights. We will not use personal information for an unrelated purpose where the Privacy Act does not permit that use.
6. Stripe and payment processing
Checkout is hosted/processed through Stripe. Information entered on Stripe pages is processed under Stripe's own terms and privacy practices. We receive information reasonably necessary to identify the transaction, product and payment status. Payment providers, banks and card networks can process information outside New Zealand.
7. Installed Omega products: local-first core operation
The reviewed ten product codebases do not require an Omega telemetry service, Omega cloud scanner, Omega image-processing API or Omega metrics account for their principal functions. Pure HTML engines use protected local server storage; WordPress plugins use the customer's WordPress environment. This statement does not describe unrelated hosting, WordPress, analytics, CDN, payment, email or third-party services the customer chooses to operate.
8. Cookies, sessions, local storage and PWA caching
The commercial website may use technically necessary browser/session storage and service-worker/PWA caching for site operation, purchase gating or user experience. Stripe and external services may use their own cookies/storage when you interact with them. The current site does not need a marketing/advertising tracking system for the core product catalogue. If that changes, this policy and any consent mechanisms will be updated where required.
9. Disclosure to service providers and others
We may disclose personal information where reasonably necessary to service providers supporting hosting, email, payments, technical operations or professional advice; to law-enforcement/regulators/courts where authorised or required; or in a lawful business transaction. We do not sell personal information as a standalone business model.
10. Overseas processing and disclosure
Some providers may process information outside New Zealand. Where Information Privacy Principle 12 applies to a disclosure to a foreign person/entity, we will use a lawful basis and take reasonable steps to ensure the conditions for overseas disclosure are met, including comparable safeguards or informed authorisation where required. The legal treatment can differ where a provider acts only as our storage/processing agent.
11. Security
We use reasonable administrative and technical measures appropriate to a commercial software website. No internet transmission or storage method can be guaranteed absolutely secure. If a privacy breach is notifiable under the Privacy Act 2020, we will follow applicable notification obligations.
12. Retention
We retain personal information only as long as reasonably required for the lawful purpose for which it may be used, including transaction/accounting records, support continuity, fraud/security evidence and legal obligations. Unnecessary sensitive support attachments may be removed earlier when no longer needed.
13. Access and correction
Subject to lawful grounds for refusal, individuals may request access to personal information we hold about them and request correction under the Privacy Act 2020. We may need to verify identity before acting on a request.
14. Marketing communications
If we send commercial electronic marketing messages, we will use consent/other lawful bases and provide sender identification and a functional unsubscribe mechanism as required by the Unsolicited Electronic Messages Act 2007. Transactional purchase, security and support communications are handled according to their purpose and applicable law.
15. Third-party links
Our site links to Stripe, social networks, Google review services and other websites. We do not control their independent privacy practices. Review their policies before providing information to them.
16. Complaints
Contact us first with details of a privacy concern so we can investigate. Individuals may also contact the New Zealand Office of the Privacy Commissioner or another competent regulator where they have the right to do so.
17. Changes
We may update this policy when our services, providers, products or legal obligations change. The version/effective date at the top identifies the current public policy.
18. Contact
Alpha & Omega Limited — OmegaWebApps
Auckland, New Zealand
Email: contact@omegawebapps.com
