Summit Hub
Legal

Privacy Policy

Version 2026-08-30 · Last updated 30 August 2026

1. About this policy

This policy explains how Summit Hub Limited, a New Zealand company ("Summit Hub", "we", "us"), handles personal information. It covers the Summit Hub web application, the client portal our customers make available to their own clients, our public website, and the emails and documents the service produces.

We follow the Privacy Act 2020 and its information privacy principles. This policy sits alongside our Terms of Service, which set out the commercial agreement. Where the two documents describe the same thing, this policy governs how personal information is handled.

2. Two kinds of personal information

Summit Hub is business software. Almost everything below turns on a distinction that is worth getting straight up front, because your rights and ours differ depending on which side of it you are standing.

Information about you. If you hold a Summit Hub account, or you are on the team of a business that does, we hold personal information about you to run that account: your name, your email address, what you did in the app. For that information we are the agency, we decide what happens to it, and this policy is our promise to you about it.

Information you hold about other people. When a builder enters or syncs their clients' details into Summit Hub — homeowners, site contacts, suppliers, trade partners — that information belongs to their business, not to us. We store and process it on their behalf, only to provide the service to them, and we do not use it for our own purposes. The builder is the agency a client should approach with a question about their own information; we help the builder answer.

So if you are a homeowner who received a Summit Hub portal invitation from your builder, the builder holds your information and their privacy policy applies to it. We hold the sign-in details that let you into their portal, and this policy applies to those. Section 11 explains what to do in each case.

3. What we collect about you

We collect:

  • Account details — your email address, your name if you give one, your role in the business you belong to, and whether your email has been confirmed by a sign-in link.
  • Sign-in and security information — the single-use sign-in links we email you, a password hash where you set a password, a two-factor authentication secret where you turn that on (encrypted at rest), and records of sign-in attempts and password resets. We do not store your password itself and cannot read it.
  • Business and billing details — your company name and branding, your plan, and the subscription and payment records that go with it. Card numbers go directly to Stripe and never reach our servers; we hold Stripe's customer and subscription identifiers, and the billing status they report back.
  • What you do in the app — the records you create and change, the documents and photos you upload, the messages you send through the app, and logs of syncs to and from the systems you connect.
  • Your conversations with the AI assistant — the messages you send it, any files you attach, and what it did in response.
  • Technical information — your IP address, browser and device type, and timestamps, captured in server logs, in security records such as rate-limit counters, and in our error monitoring when something goes wrong.

We collect this from you directly, from the team member who invited you, from the systems your business connects to Summit Hub, and automatically as you use the service. We do not buy personal information from anyone, and we do not build profiles of you for advertising.

4. Why we use it

We use personal information to:

  • provide the service — run your account, sync your connected systems, produce your documents, and show your team and your clients what they are meant to see;
  • sign you in and keep the service secure, including detecting and stopping abuse;
  • bill you, and handle plan changes, failed payments and refunds;
  • send you service messages — sign-in links, portal and quote emails, notifications you have turned on, changes to our terms or this policy, and anything we are legally required to tell you;
  • support you when you contact us, and diagnose faults;
  • improve the service, understand which features are used, and plan what to build next; and
  • meet our legal obligations and, if it ever comes to it, establish or defend a legal claim.

We do not sell personal information. We do not use the contents of your account, or the personal information you hold about your clients, to train AI models — see section 5.

5. The AI assistant

Summit Hub includes an AI assistant that answers questions from your business information. To produce an answer, your message, any files you attach, and the records needed to answer are sent to our AI provider (currently Anthropic) for processing, and the reply comes back to you. We use the provider's business terms, under which your content is not used to train their models.

Only send the assistant information you are comfortable having processed this way. If you would rather not use it at all, it can be turned off for your account — ask us.

6. Who we share it with

We share personal information only with the providers we need to run the service, with the systems you yourself connect, and in the limited circumstances listed below. The providers we engage to run Summit Hub are bound by our agreements with them to use it only to provide their service to us. That does not cover the systems you connect: you authorise those under your own agreement with each provider, and their privacy terms govern what they do with the information once it reaches them. The list below is everyone.

  • Voyager Internet Limitedour application servers, database, job queue and file storage run on infrastructure we control, on a virtual server this New Zealand provider hosts for us. Your documents, photos and generated spreadsheets are stored on that same infrastructure, encrypted at rest, rather than in a third-party document service.
  • Cloudflareserves our DNS and sits in front of the application as a reverse proxy, so every request to Summit Hub passes through their global network — the address you asked for, what you sent with it, and your IP address — before it reaches our servers.
  • Resendsends our transactional email: sign-in links, invitations, portal and quote emails, notifications.
  • Stripetakes and processes subscription payments, and holds the card details we never see.
  • Anthropicprocesses AI assistant requests (section 5).
  • Sentryreceives application error reports so we can fix faults. We have user-identifying capture switched off, but an error report can still incidentally contain information from the request that failed.
  • The systems you connectHubSpot, Xero, Buildxact, Notion and any others you authorise. Information flows to and from these because you asked it to, and once it is in one of them, that provider's own privacy terms apply as well as ours.
  • Professional advisers, and where the law requires itour accountants and lawyers under a duty of confidence, and any disclosure the law compels or that is needed to prevent a serious threat to someone's safety.
  • A buyer of our businessif Summit Hub is sold or restructured, account information transfers with it, and we will tell you before that happens.

We do not otherwise disclose the personal information you hold about your clients to anyone, and we do not share it between customers. Each business's data is separated from every other business's.

7. Information sent overseas

Our application servers, our database, and the file storage holding your documents and photos are in New Zealand, on a virtual server hosted for us by Voyager Internet Limited. Encrypted backup snapshots are taken on that server and copied to a separate off-host destination we control.

Requests reach those servers through Cloudflare, which terminates the encrypted connection at whichever of its locations is nearest you — so what you send passes outside New Zealand on the way in, even though it comes to rest here. Some of the providers in section 6 — Resend, Stripe, Anthropic, Sentry, and the systems you connect — process information outside New Zealand, including in the United States, Australia and the European Union.

Before we send personal information to a provider overseas we satisfy ourselves, as principle 12 of the Privacy Act 2020 requires, that they are subject to comparable safeguards — through their contractual commitments, their published data-protection terms, and the privacy laws that apply where they operate. Information you send to a system you have connected yourself goes wherever that provider holds it, under your agreement with them.

8. Keeping it secure

We protect personal information with reasonable safeguards: encrypted connections, encryption of stored credentials and uploaded files, access controls that keep each business's data separate, two-factor authentication available on every account, single-use sign-in links that expire, rate limiting on the paths an attacker would push against, and regular encrypted backups kept away from the production servers.

No system is completely secure, and we cannot promise that nothing will ever go wrong. You have a part in this too: keep the email account you sign in with secure, turn on two-factor authentication, remove access when someone leaves your team, and check what a client will see before you share it with them.

9. How long we keep it

We keep personal information only as long as we need it for the purposes in section 4, or as long as the law requires.

  • While your account is open — we keep your account information and your business's content for as long as the account exists, because that content is the service.
  • After your account closes — your content is kept for at least 30 days before it can be permanently deleted, so you have time to ask us for a copy. After that it is deleted from live systems and ages out of our backups on their normal rotation.
  • Records we have to keep — billing and tax records for the seven years the Inland Revenue requires, and evidence records such as e-signing audit trails and security logs for as long as they might be needed to show what was agreed or what happened.
  • Backups — encrypted backup snapshots rotate on a fixed schedule and are then destroyed. Information deleted from the live service can persist in a backup until that snapshot expires.

10. Cookies and how the site is measured

The app sets the cookies it needs to keep you signed in and to protect the sign-in process. These are strictly necessary — the service does not work without them.

We do not use advertising cookies, we do not run third-party advertising or analytics trackers on our site, and we do not track you across other websites. Our error monitoring runs in your browser to report faults; it is not an analytics tracker and does not follow you elsewhere.

11. Seeing and correcting your information

Under principles 6 and 7 of the Privacy Act 2020 you can ask to see the personal information we hold about you, and ask us to correct it if it is wrong.

If we hold it about you — because you have or had a Summit Hub account — email us at the address in section 14. We will need to be satisfied you are who you say you are. We will respond as soon as we can and within 20 working days, as the Act requires. Most account details you can simply correct yourself in Settings. If we decline a request, we will tell you why and tell you that you can complain to the Privacy Commissioner.

If a Summit Hub customer holds it about you — because you are a client, contact or trade partner of a business that uses Summit Hub — that business is the one to ask, and their privacy policy applies. If you approach us instead, we will point you to them, and where we can identify the business we will pass your request on. We will not disclose or change information held on a customer's behalf without their instruction, except where the law requires it.

Summit Hub customers: when one of your clients asks you for their information, everything you need is in the app, and we will help you assemble it if you ask.

12. If something goes wrong

If a privacy breach happens and it is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and the people affected as soon as practicable, as the Privacy Act 2020 requires.

Where a breach affects information a customer holds on their clients, we will tell that customer as soon as practicable after we confirm it, with the detail they need to assess the harm and meet their own notification obligations. They, not we, decide what to say to their clients, unless the law obliges us to notify people directly.

If you think your information has been compromised, tell us straight away at the address in section 14.

13. Changes to this policy

We may update this policy — when we add a provider, collect something new, or change how long we keep something. The current version, with its version number and date, is always at summithub.co.nz/privacy. If a change materially affects how we handle information about you, we will tell you by email or in the app before it takes effect.

14. Contact us, and complaints

Privacy questions, requests to see or correct your information, and breach reports all go to:

Summit Hub Limited
[email protected]

If you are not happy with how we have handled your privacy, please raise it with us first — we would rather fix it. If we cannot resolve it, you can complain to the Office of the Privacy Commissioner at privacy.org.nz, on 0800 803 909, or at PO Box 10094, Wellington 6143. Complaining costs nothing.