Privacy policy

What we collect, why we collect it, who it goes to, and what you can ask us to do about it — including the information you hold about your own customers.

Last updated 25 July 2026

1. Who we are

GoSmoko is operated by Smoko Software Limited (NZBN 9429000000000), based in New Plymouth, Taranaki. Our postal address is 23 Currie Street, New Plymouth Central, New Plymouth 4310, Taranaki, New Zealand.

We have a named privacy officer, as the Privacy Act 2020 requires. Reach them at privacy@gosmoko.com — a person reads that inbox, not a ticket queue.

2. Scope of this policy

This policy covers personal information GoSmoko handles: information about you as a user, and information about your customers that you enter into GoSmoko. It covers the website, the web app, and the GoSmoko app for iPhone and Android equally.

For your own business data, you are the one who decides what is collected and why — we hold and process it on your behalf. For information about you as our customer, we make those decisions.

We handle personal information in line with the New Zealand Privacy Act 2020 and, where it applies, the Australian Privacy Principles.

3. What we collect about you

  • Account details: your name, email address, and the business details you enter — legal name, trading name, address, phone, website, GST number, and bank account for invoice footers.
  • Sign-in information: a password hash, or the identity your Google account returns if you sign in that way. We never see or store your Google password.
  • Billing information: your plan and billing history. Card details are held by our payment processor, not by us.
  • Technical information: IP address, browser and device type, and timestamps of requests, kept to keep the service secure and diagnose faults.

4. What you put in about your customers

To do its job, GoSmoko stores the customer records you create: name, email, phone, addresses, site notes, and the jobs, quotes, and invoices attached to them.

This is your information about your customers. We only use it to provide the service to you — displaying it back to you, rendering it onto the quotes and invoices you send, and passing it to the integrations you have connected.

We do not market to your customers, and we do not use their details for anything other than running your account.

5. The mobile app

The iPhone and Android app is offline-first, which means it keeps its own copy of your business on the phone so it works with no signal. That copy is encrypted at rest with a key held in the phone's own keychain or keystore, and you can require Face ID, Touch ID or a fingerprint to open the app.

Signing out deletes that local copy entirely. Nothing about your integrations — no Xero token, no Stripe key, no email API key — is ever stored on the device.

  • Camera: only opened when you tap to take a job photo. Photos are attached to the job you were on and uploaded when you have signal. We do not read your photo library.
  • Microphone and speech: only active while you hold the mic or use Talk it out. The kept transcript is read by Whisper from a short recording we do not store — the audio is discarded after the words come back. If you then run AI triage, that text is sent for extraction.
  • Location: stamped when you start or end the work day, and when you clock a job on its own — that part is not live tracking. Clocking on also maps that workday (drive vs stop) so you can put hours on jobs at knock-off. That map is yours: only you see it, your employer cannot turn it on for you or read your movements, and it is not a live tracker. You can pause mapping for the day or turn it off in Settings. Raw location points are deleted after 90 days. The time allocations you confirm stay visible as normal timesheet records.
  • Photos: stamped with the same location at the moment you take them, so a photo can prove where and when work happened. That stamp travels with the photo; only you and people already on the job see it.
  • Push notifications: if you turn them on, we store a device token from Apple or Google so we can send you a notification. Turning them off in your phone settings stops it.
  • No advertising identifier is read, no analytics SDK is bundled, and no data is used for tracking as Apple defines it. There is nothing to opt out of because there is nothing collecting.

6. How we use information

  • To run the service: storing your records, generating documents, calculating GST at the rate you set, and producing your reports.
  • To send the emails you ask us to send, on your behalf, through GoSmoko email (Hatched Send, operated by our tech partner Hatched Digital).
  • To keep the service secure: detecting misuse, verifying webhooks, and investigating faults.
  • To bill you, and to contact you about your account, billing, or a security matter.
  • To improve GoSmoko in aggregate — which features are used, where errors occur. This never involves reading your customers' details.

7. Artificial intelligence

The smart inbox uses an AI model to pull structured fields out of text you paste or speak, such as a job you talked in, a voicemail, or an enquiry email. Short voice recordings are sent to Whisper to turn into that text, then discarded. Only the resulting text is sent for extraction.

Your customer list, your pricing, your invoices, and your reports are not sent to any AI provider. Nothing from your account is used to train models, by us or by our providers.

If you would rather not use it, leave the smart inbox alone — the rest of GoSmoko works without it.

8. Who we share information with

We share information with service providers who help us run GoSmoko, and only what each needs:

  • OpenAI, to turn a short voice recording into text and to extract fields from text you asked us to read. The recording is not kept.
  • Hatched Digital (Hatched Send), to deliver the emails you send — the recipient address and the document contents.
  • Stripe, when you create a payment link — the amount, currency, invoice number, and reference.
  • Xero or MYOB, when you push an invoice — the customer contact details, line items, and totals.
  • Our payment processor, for your own subscription billing.
  • Apple and Google, to deliver push notifications to your phone if you enable them.

9. Where information is stored

Data is held in managed infrastructure with encryption at rest and automated backups. Some providers operate outside New Zealand and Australia, which means information may be stored or processed overseas.

Where that happens, we use providers that are contractually required to protect information to a standard comparable to the Privacy Act.

Every company that can touch your data is named individually on our sub-processors page, along with what it does and which country it holds data in. We publish that list because a privacy policy you cannot check is not worth much.

10. How we protect it

  • Integration credentials — API keys and OAuth tokens — are encrypted with AES-256-GCM before being written to the database, using a key held outside it.
  • Every record is scoped to the business that owns it, and every query is filtered by the signed-in user's business.
  • Customer-facing quote and invoice links use unguessable random tokens, expose one document each, and are excluded from search engines.
  • Incoming payment webhooks are verified against your own signing secret before anything is marked paid.

11. How long we keep it

We keep your account data while your account is open. You can delete your business yourself at any time, from Settings in the app or on the web — it is immediate and permanent, and our account deletion page sets out exactly what goes and what briefly remains.

After deletion, encrypted database backups age out within 7 days and email delivery logs within 30. Neither can be used to reconstruct your customer list or job history.

Some records are kept longer where the law requires it, such as billing records for tax purposes. Integration credentials are deleted immediately when you disconnect an integration.

12. Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email privacy@gosmoko.com and we will respond within 20 working days.

Deletion does not need to go through us at all: Settings in the app and on the web will delete your whole business immediately. Ask for an export first if you want one, because afterwards we genuinely cannot get it back.

If one of your customers asks you about information you hold about them in GoSmoko, that request is yours to answer — you can view, correct, and delete their records yourself. We will help if you need it.

If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Privacy Commissioner in New Zealand, or the OAIC in Australia.

13. Cookies

We use one session cookie, to keep you signed in. That is functionally necessary — without it you would be signed out on every page — which is why there is no consent banner to dismiss.

We do not use advertising cookies and we do not run third-party trackers on the marketing site. The mobile app uses no cookies at all. Our cookies page lists the single cookie in full.

14. Changes and contact

If we change this policy in a way that materially affects you, we will notify you by email or in the app before it takes effect.

For any privacy question, email our privacy officer at privacy@gosmoko.com. For a security concern, email security@gosmoko.com and we will confirm receipt within two business days.

Post reaches us at 23 Currie Street, New Plymouth Central, New Plymouth 4310, Taranaki, New Zealand.

This document is written to be read, not to be impenetrable. If anything in it is unclear, email hello@gosmoko.com and we will explain it in plain terms.