Privacy at Criollo Designer Cakes

Privacy Statement

This statement explains how Criollo Designer Cakes NZ Ltd collects, uses, stores and shares personal information when you browse our website, request a quote, place an order, arrange a gift or delivery, contact us, or otherwise deal with our business.

Applies from: 2 August 2026 Law: New Zealand Privacy Act 2020 Business: Criollo Designer Cakes NZ Ltd
We collect what we need

We use relevant information to quote, make, sell, deliver and support your order.

We do not sell your data

We do not sell, rent or trade customer or gift-recipient information.

Card details stay protected

Complete card numbers and security codes are handled by our payment provider, not stored by us.

You can contact us

You may ask to access or correct the personal information we hold about you.

Who we are

In this statement, “Criollo”, “we”, “us” and “our” mean Criollo Designer Cakes NZ Ltd. We trade as Criollo Designer Cakes and may also use the trading name The Cake Lady Dunedin. We are the agency responsible for personal information collected through criollo.co.nz and through our direct dealings with customers and recipients.

Criollo Designer Cakes NZ Ltd
Trading as Criollo Designer Cakes
Dunedin, Otago, New Zealand
Privacy Officer: Business Owner / Privacy Officer
Privacy contact address (email): criollo.designer.cakes@gmail.com
Phone: 022 021 7238
This statement does not remove your legal rights. It should be read with our Terms and Conditions and Cookie Policy. Nothing in those documents limits rights that cannot lawfully be excluded.

What personal information we collect

Personal information means information about an identifiable individual. What we collect depends on how you interact with us.

Quotes, orders and deliveries

  • Your name, preferred name and, if supplied, preferred pronouns
  • Email address, telephone number and delivery or billing address
  • Event date, occasion, serving number, flavour, filling, design and budget
  • Dietary requests and other information relevant to the product
  • Cake or cupcake inscriptions, names, ages and personalised details
  • Uploaded inspiration images, logos, photographs or design files
  • Order, invoice, deposit, refund, payment-status and delivery records

Website and communications

  • Messages sent by email, form, phone, text, Facebook, Instagram or WhatsApp
  • Customer-service, cancellation, complaint, refund and dispute information
  • Account details if you choose to create a website account
  • IP address, browser, device, approximate location and website activity
  • Cookie preferences and analytics information where enabled
  • Any review, testimonial or feedback you choose to provide

Required and optional information

Information needed to identify you, communicate with you, price and make an order, process payment, arrange pickup or delivery, and meet legal record-keeping duties is required for those purposes. If you do not provide it, we may be unable to give an accurate quote, accept or fulfil an order, process a payment, or complete a delivery. Information described as optional may be withheld, although this may limit how closely we can personalise the product or service.

Dietary information and unnecessary personal details

Please provide only the dietary information reasonably needed for the product. We use it to assess and respond to your request, but providing dietary information does not alter the allergen and shared-kitchen provisions in our Terms and Conditions. Please do not send medical records, identity documents, financial account passwords, or other sensitive information that we have not requested.

Why we collect and use personal information

We collect and use personal information for lawful purposes connected with our business, including to:

  • respond to an enquiry and prepare, discuss or revise a quote
  • check availability and plan production for the requested date
  • create and personalise cakes, cupcakes, cupcake bouquets, desserts and gifts
  • process orders, deposits, payments, refunds and custom-payment requests
  • arrange pickup or delivery and communicate with a purchaser or recipient
  • provide customer service and manage changes, cancellations or complaints
  • confirm dietary requests without guaranteeing an allergen-free environment
  • detect or prevent fraud, misuse, suspicious transactions and security incidents
  • manage chargebacks, debts, insurance matters, disputes and legal claims
  • maintain accounting, GST, tax and other legally required business records
  • operate, secure, troubleshoot and improve our website and services
  • measure website use and advertising performance where permitted
  • send marketing where permitted by law and in accordance with your choices
  • comply with lawful requests, court orders and regulatory obligations

We will not use personal information for a materially different purpose unless that use is permitted by law or we take reasonable steps to tell you and obtain authorisation where required.

Gift recipients and information collected from other people

A purchaser may give us another person’s name, phone number, address, occasion, gift message or delivery instructions so that we can prepare and deliver a gift. We may also receive personal information from an authorised representative, payment or fraud-prevention provider, social-media service, or another person acting on your behalf.

How we handle recipient information

  • We use it only for the order, delivery, customer service, safety, record-keeping and related lawful purposes.
  • We do not add a gift recipient to a marketing list merely because someone sent them a gift.
  • The purchaser should provide accurate information and only what is reasonably necessary.
  • Where reasonably practicable, we will make a recipient aware of our collection when we first contact them.
  • For a genuine surprise gift, notice may be delayed or omitted where a lawful Privacy Act exception applies because earlier notice would defeat the purpose of the collection or would not prejudice the recipient’s interests.
For purchasers: please make sure you are entitled to give us a recipient’s details. Do not provide private or sensitive information that is not needed to prepare or deliver the order.

Children’s information

Our ordering services are intended for people capable of placing an order. We do not knowingly collect children’s information for direct marketing. Names, ages, photographs or interests may nevertheless appear in a cake design, inscription or inspiration image supplied by an adult. Please provide only what is necessary. A parent or guardian may contact our Privacy Officer about personal information concerning a child.

Who may receive personal information

We disclose only information reasonably required for the relevant purpose. Depending on the service you use, recipients may include:

  • Website and store providers — our hosting and technical-support providers, WordPress, WooCommerce and related service providers
  • Payment providers — WooPayments, Automattic, Stripe, relevant banks, card networks and fraud-prevention services
  • Communication providers — Google/Gmail and, when you choose those channels, Meta services such as Facebook, Instagram and WhatsApp
  • Website tools — analytics, mapping, cookie-consent, review-display, security and performance providers that are enabled on our site
  • Business support — authorised staff, delivery personnel, accountants, insurers, legal advisers and IT support who need the information for their work
  • Authorities and enforcement — regulators, courts, tribunals, Police or other agencies where disclosure is required or permitted by law
  • Business transactions — a genuine prospective purchaser, adviser or successor if our business is sold, merged or restructured, subject to confidentiality and applicable law

Some services collect information directly under their own privacy policies. When you intentionally leave our website or use a third-party social, payment or mapping service, that provider’s terms and privacy practices may also apply.

Overseas processing

Some technology, payment, email, analytics and social-media providers may process information outside New Zealand, including in the United States and other countries in which they or their service providers operate. Where Information Privacy Principle 12 applies, we take reasonable steps to ensure that the overseas recipient is subject to the New Zealand Privacy Act 2020, comparable privacy safeguards, or contractual protections, or we seek informed authorisation where the law requires it.

We do not sell personal information. We do not sell, rent or trade customer or gift-recipient details to unrelated businesses for their own marketing.

Cookies, analytics and marketing

Cookies and similar technologies

Our website uses cookies and related technologies to keep the shop and cart working, remember choices, protect the website, understand site use and, where enabled, measure or support marketing. These may collect an IP address, device or browser details, page activity, referring information and cookie identifiers.

Necessary cookies support functions requested by you, such as the shopping cart, checkout, security and stored privacy preferences. Statistics, preference or marketing technologies are handled in accordance with the choices offered by our consent tool. You can change your selection through the Manage Consent control in the website footer. More information is available in our Cookie Policy.

Marketing messages

We may send news, offers or product updates only where permitted by New Zealand law. Marketing messages will identify Criollo Designer Cakes and include a clear, usable way to unsubscribe. We action a valid unsubscribe request within five working days. You may also withdraw marketing permission by contacting our Privacy Officer. Order confirmations, quote discussions, delivery messages, safety information and responses to your requests are service communications rather than marketing.

Customer images, finished cakes and our portfolio

Inspiration images, logos and photographs supplied by a customer are used to assess, quote and make the requested product. Please provide them only if you are entitled to do so. We may photograph our completed cakes, cupcakes and desserts for quality records, our gallery, social media and business promotion. We avoid publishing contact details, delivery addresses, private correspondence or other unnecessary information. Where an image includes a recognisable person or unusually sensitive identifying information, we will seek permission or remove or obscure that information before publication. Please tell us before collection or delivery if an order or design is confidential.

How long we keep information and how we protect it

Retention

We retain personal information only for as long as it is reasonably required for a lawful purpose. Different records are kept for different periods:

Orders and financial records Normally at least seven tax years where required for accounting, GST, tax and audit purposes.
Accepted quotes and order correspondence Kept with the relevant order record where needed to show what was requested, agreed, made and delivered.
Unsuccessful quotes and general enquiries Normally deleted or anonymised within 24 months after the last meaningful contact, unless a dispute or legal reason requires longer retention.
Uploaded designs and personal images Normally retained only with the relevant enquiry or order and removed when no longer needed, unless we have permission for portfolio use or they are required for a dispute.
Marketing preferences Kept until you unsubscribe. We may retain a minimal suppression record so that we remember not to send further marketing.
Cookies and analytics Kept for the periods identified by our cookie-consent tool and Cookie Policy.

Information may be kept longer where reasonably needed for an active complaint, chargeback, debt, insurance matter, legal claim, investigation or statutory duty. Deleted information may remain for a limited period in protected backup systems until those backups are securely overwritten through the normal backup cycle.

Security

We take safeguards that are reasonable for the nature of the information and our business. These include limiting access to people who need it, using secured website connections and reputable service providers, maintaining website software and access controls, and taking reasonable steps to prevent loss, misuse, unauthorised access, alteration or disclosure. No internet transmission or storage system can be guaranteed to be completely secure.

Payment-card information

Card payments are processed using WooPayments and its payment partners, including Stripe. Complete card numbers and card security codes are entered into secure payment fields provided by the payment service and are not stored in our WordPress database. We may receive and retain limited transaction information such as payment status, transaction identifiers, card brand and the last digits of a card where provided by the payment service. Those records help us reconcile payments, issue refunds, prevent fraud and manage disputes.

Privacy breaches

If a privacy breach has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, unless a lawful exception applies. We will also take reasonable steps to contain the breach and reduce the risk of further harm.

Your access, correction and complaint rights

Under the Privacy Act 2020, you may:

  • ask whether we hold personal information about you
  • request access to personal information we hold about you
  • ask us to correct information that is inaccurate, incomplete or misleading
  • provide a statement of correction if we do not make a requested correction
  • ask us to delete information that is no longer needed, subject to our legal and lawful retention requirements
  • withdraw permission for optional marketing and change cookie preferences
  • complain about how we have handled your personal information

Please contact our Privacy Officer using the details below. Describe the information or issue clearly. Before releasing or changing information, we may ask for reasonable evidence of identity or authority so that we do not disclose information to the wrong person. We will make and communicate a decision on an access or correction request as soon as reasonably practicable and no later than 20 working days, unless an extension is permitted by law. Access may be withheld only where the Privacy Act allows it.

How to complain

We encourage you to contact us first so that we can investigate and try to resolve the matter. If you are not satisfied, you may complain to the Office of the Privacy Commissioner.

Privacy Officer: Criollo Designer Cakes NZ Ltd
Email: criollo.designer.cakes@gmail.com
Phone: 022 021 7238
Privacy contact address: criollo.designer.cakes@gmail.com

Changes to this statement

We may update this statement when our services, providers, business practices or legal obligations change. The current version will be posted on this page with a revised effective date. If a material change affects how we intend to use personal information already collected, we will take reasonable steps to notify affected people and obtain authorisation where required by law.

Questions about your privacy?

Contact our Privacy Officer if you want to ask a question, request access or correction, raise a concern, or withdraw from optional marketing.

Criollo Designer Cakes NZ Ltd · Dunedin, Otago, New Zealand · Last updated 2 August 2026

0