Jingle Jandals / Ripper Christmas — operated by Stackdtec Limited, New Zealand. Contact: hello@ripperchristmas.com.
Last updated: 4 October 2026
Draft for owner review — not legal advice.
We take privacy seriously and keep things simple: we collect only what we need to make and deliver your video cards. This policy explains how we handle personal information under the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs), and, where it applies to us, the Australian Privacy Act 1988 and Australian Privacy Principles (APPs).
About you (the customer):
About your recipients:
We ask you to upload names only — no addresses, phone numbers or other details.
When you upload recipient names, we hold and use them only on your behalf, to make your cards, and not for our own purposes. We don't contact recipients, market to them, or sell or share their names.
You (the customer) are responsible for having collected those names lawfully and for being open with your clients about how you use their information, including any notification they need (for example, under NZ IPP 3, and IPP 3A for information collected indirectly from 1 May 2026). See section 6 of our Terms.
If a recipient contacts us about their information, we'll usually refer them to the business that sent the card, and help where we can.
We use trusted service providers to run the service. They handle information on our behalf and under their own security and privacy commitments:
People who open a share link can see that card, including the recipient's name. Share links use hard-to-guess IDs but are not password protected — anyone with the link can view the card.
We may disclose information if required by law. We don't sell personal information.
Our service is hosted in Sydney, Australia, and Stripe may process payment data in the United States and elsewhere. Where a provider simply stores or processes information for us, we remain responsible for it under the NZ Privacy Act. Where information is disclosed overseas, we take reasonable steps (IPP 12) to make sure it is protected by comparable safeguards — for example through the provider's contractual and security commitments.
We use reasonable safeguards, including encrypted connections (HTTPS), access controls, and storage with reputable providers. No system is perfectly secure. If a privacy breach is likely to cause serious harm, we'll notify affected people and the Privacy Commissioner as required by law (and the OAIC where the Australian scheme applies).
You can ask to see the personal information we hold about you and ask us to correct it (IPPs 6 and 7; APPs 12 and 13). Email hello@ripperchristmas.com. We'll respond within 20 working days and won't charge for a request. We may need to verify your identity.
We aim to: collect only what we need (IPP 1), mostly directly from you (IPP 2), tell you why (IPPs 3 and 3A), collect fairly (IPP 4), keep it secure (IPP 5), let you access (IPP 6) and correct it (IPP 7), keep it accurate (IPP 8), keep it no longer than needed (IPP 9), use (IPP 10) and disclose (IPP 11) it only for the purposes we collected it, protect it when sent overseas (IPP 12), and use unique identifiers only where appropriate (IPP 13).
If we're covered by the Australian Privacy Act, we'll handle information in line with the APPs. Many small businesses with annual turnover of A$3 million or less may be exempt; confirm the position before launch. Either way, we apply the same practices described here to Australian customers.
Contact us first at hello@ripperchristmas.com and we'll do our best to help.
If you're not satisfied:
We may update this policy and will post the new version here with a new "last updated" date.