Draft. Not yet reviewed by a lawyer. Dev only.

DRAFT prepared with AI assistance, 26 September 2026. Internally reviewed against NZ law but NOT reviewed by a lawyer. Do not publish until a New Zealand lawyer has approved it. See REVIEW.md.

My Shout privacy policy

Effective date: [DATE]. Version [1.0].

My Shout (myshout.nz) is run by NetPotential Limited, trading as Growth Spurt, of [REGISTERED OFFICE OR POSTAL ADDRESS], Auckland, New Zealand (NZBN [NZBN]). In this policy "we", "us" and "our" mean NetPotential Limited. We are the agency that collects and holds your information under the Privacy Act 2020, and we are the promoter of every My Shout draw.

This policy tells you what we collect, why, who sees it, where it goes, how long we keep it, and how to see, fix or delete it. It also tells you how the draw log works, because the way we publish draws is unusual and you should understand it before you play.

Privacy questions: privacy@myshout.nz.

Note for the lawyer: confirm the postal address to publish. IPP3 requires the name and address of the agency collecting and holding the information.

1. The short version

2. Who this policy covers

This policy covers players, people who visit myshout.nz, people who chat with Shona, and people at sponsor businesses who deal with us. Sponsors' own websites, shops and marketing have their own privacy policies, which we do not control.

My Shout is for New Zealand residents aged 18 or over. If you are under 18, please do not sign up. If we learn that a player is under 18 we will close the account and delete the information we hold, subject to section 10.

3. What we collect, and why

We collect only what the game needs. Each item below says where it comes from, why we need it, and who else sees it.

3.1 Your mobile number and login

What: Your mobile number, the one-time login code you text us, the time and content of that text, and the reply we send you.

How: You log in by texting a short code shown on screen to our My Shout number. Your carrier delivers that text to our own SMS gateway, which runs on a server in New Zealand. If our gateway is busy or down we may send replies and winner notices through a backup SMS provider [NAME PROVIDER(S) BEFORE LAUNCH, for example ClickSend, MessageMedia or Twilio], which receives your number and the message text in order to deliver it.

Why: One verified mobile number is one player, which is how we keep the draw fair. We also use it to text you if you win, and for nothing else unless you opt in to something.

How we store it: We keep a one-way hash of your number so we can recognise you when you log in again, and an encrypted copy so we can text you. Staff and systems that do not need to send texts see only the hash.

Who else sees it: Your carrier and, if used, the backup SMS provider. Nobody else. Sponsors never see your number.

If you do not provide it: You can browse the site and play practice questions, but you cannot enter a draw or win a prize.

Number checks: We may check your number against a lookup service to reject virtual (VoIP) numbers, which are the usual tool for creating fake accounts.

Note for the lawyer: naming the lookup provider and confirming the number goes overseas for that check. If the provider is offshore, this section becomes an IPP12 disclosure unless the provider acts purely as our processor.

3.2 Logging in with Google, Facebook or X (optional)

You can also sign in with a Google, Facebook (Meta) or X account. This is a convenience. It is optional, and you still need a verified mobile number before you can enter a draw.

When you use one of these, the provider sends us a small set of profile information. We ask for the minimum each provider allows for sign-in:

Provider What we receive What we do with it
Google Your Google account ID, name and profile picture Sign you in, pre-fill your display name, show your picture in My Account
Facebook (Meta) Your app-scoped Facebook ID, name and profile picture Same
X Your X user ID, display name, username (handle) and profile picture Same

We store the provider's ID for your account so we can match you next time, plus the name and picture. We discard the access token once sign-in is complete, unless you use a feature that needs it. We do not:

Google user data. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use your Google information only to sign you in and run your My Shout account, we do not sell it, we do not use it for advertising, and humans at NetPotential only look at it with your consent, for security, or where the law requires.

Facebook and X data. We use information from Meta and X only for sign-in and your account, as their platform terms require. If you remove My Shout from your Facebook or X settings, or ask us to, we delete the information we received from that provider. If you delete your X account or content, we delete what we hold from X within 24 hours of being told.

Unlinking. You can unlink a social login in My Account, or from the provider's own settings (Google: myaccount.google.com/permissions; Facebook: Settings, Apps and Websites; X: Settings, Security and account access, Apps and sessions). Unlinking does not close your My Shout account, because your account is anchored to your mobile number.

3.3 Home region

What: The region you choose at sign-up (for example Rotorua or North Shore), when you chose it and when you last changed it.

Why: Your region decides which prizes you play for and which draw you enter. You can change it once every 30 days.

Who else sees it: It is visible to sponsors only as a count (how many players their region has). If you win, the sponsor learns the region the prize was for, because that is where it is redeemed.

3.4 IP address and coarse location signals

What: The IP address your device connects from, the approximate location our hosting provider derives from it (country and region level, not a street address), your browser's time zone and language, and, if you choose to allow it, your device's approximate location from the browser.

Why: Two reasons. First, to check that your home region is plausible: a Rotorua player who always connects from Auckland gets flagged for a human to look at. Second, to detect fraud, such as many accounts from one device or network. We never block or void an entry on location signals alone; a person reviews flagged cases against the terms of entry.

Browser location: We only ask your browser for location after you tap a button asking for it, and you can say no. The site works without it.

Who else sees it: Our hosting provider (Cloudflare) processes IP addresses to deliver the site and to protect it from attack. Nobody else.

3.5 Device, sessions and push notifications

What: A long-lived device token stored on your device so you do not have to text us every day, the browser and device type, when the device was last seen, and, if you turn on notifications, a push subscription (an endpoint address issued by your browser or phone maker, plus the keys needed to encrypt messages to it).

Why: To keep you logged in on your device, to send you the "live in 5 minutes" and result notifications you asked for, and to spot one device running many accounts.

Push notifications are opt-in. We ask only after you tap a button. You can turn them off any time in My Account or in your phone's settings. We limit how many we send, we do not send them during quiet hours, and we delete subscriptions that stop working. On iPhone and iPad you need to add My Shout to your Home Screen before notifications can be turned on.

Who else sees it: Push messages travel through your browser or phone maker's push service (Apple, Google or Mozilla, depending on your device). They are encrypted so the push service cannot read them.

Note for the lawyer: whether a push notification about a sponsor's deal is a "commercial electronic message" under the Unsolicited Electronic Messages Act 2007. Our working assumption is to treat push like SMS: notifications about the game are fine; any push that promotes a sponsor's deal needs the same consent, sender identification and unsubscribe as a marketing text. Please confirm.

3.6 Gameplay

What: Which quiz you played, each answer you gave, how long each answer took, your score, streaks, whether you played the live game or the anytime quiz, and team boards you joined (suburb, school or workplace).

Why: To run the game, work out your entries, show leaderboards, and detect cheating (impossible reaction times, answers before the question was revealed, bots).

Who else sees it: Leaderboards show your display name and score to other players. You choose your display name and you can use a nickname. Team boards show participation rates, not individual answers. Sponsors see aggregate figures for their sponsor question (how many players answered, how many got it right), never individual answers.

3.7 Draw entries and the public draw log

This is the part that is different from most games, so please read it.

Every day, at the moment entries close, we seal the entry list for each region and publish a commitment to it in a public log at myshout.nz/draws. The commitment contains the number of entries, a Merkle root (a single fingerprint of the whole list), a public randomness round number and our digital signature. We also send a hash of that commitment to the OpenTimestamps service, which anchors it on the Bitcoin blockchain, and we use the League of Entropy's public randomness beacon (drand) to pick winners.

What is public: For each of your entries, the log contains a leaf. A leaf is a hash of the draw ID, an internal player ID, the entry number and a random secret (your salt) that only we hold. Because of the salt, nobody can work backwards from the log to you, and nobody can tell whether two leaves belong to the same person. The log also contains a group fingerprint per player for that draw, again salted, so a verifier can check that one person did not win twice without knowing who anyone is.

What is sent outside: OpenTimestamps receives only a hash of the commitment. It never receives leaves, names, numbers or any personal information. drand receives nothing from us: we only read its public randomness.

Why we do it this way: So anyone can check that the draw was fair, and so we cannot quietly change the list after the fact.

What it means for deletion: Published leaves are permanent. They are part of a record that other people rely on to verify draws, and once anchored on Bitcoin they cannot be withdrawn. When you delete your account we delete your salt and your internal player ID, after which your leaves cannot be linked to you by us or anyone else. See myshout.nz/data-deletion.

Prove my entry: In My Account you can download your own salt, leaves and proofs to confirm you were in a sealed list. Anyone you give them to could check that too, so keep them to yourself if you care about that.

Note for the lawyer: our position is that a salted hash in the public log, with the salt deleted on account closure, is not personal information about an identifiable individual once the salt is gone. Please confirm this reasoning, and whether the retention wording in section 9 is enough.

3.8 Winners

What: If you win, we record which prize, which draw, when we told you, when you claimed and when the sponsor redeemed your code.

Who else sees it:

Note for the lawyer: some promoters publish winners' names as a Fair Trading Act transparency measure. We have made publication opt-in. Please confirm that opt-in is compatible with the terms of entry and that we do not need to publish winners to satisfy any rule.

3.9 Consent records

What: Each time you agree to something (the terms of entry, this policy, the 18+ confirmation, push notifications, winner publication, a sponsor's marketing) we record what you agreed to, the version of the wording, when, and from which screen or message.

Why: So we can prove what you agreed to and honour it, and so you can see it in My Account.

3.10 Sponsor marketing opt-ins (optional, and separate for each sponsor)

Sponsors sometimes offer a deal to every player in their region on the day they shout. Claiming a deal does not give the sponsor your details. It gives you a code.

Separately, you may tick a box to let a particular sponsor contact you. That box is:

If you tick it we pass that sponsor your name (as you gave it to us), your mobile number and/or email address, your region, and the fact that you opted in and when. From that point the sponsor is a separate agency under the Privacy Act, responsible for how it uses your details and for honouring your unsubscribe. We require sponsors in our agreement to use the details only for their own marketing, to identify themselves in every message, to honour unsubscribes, and never to pass your details on. You can withdraw an opt-in in My Account; we will tell the sponsor, but messages already in flight may still arrive.

Note for the lawyer: confirm the opt-in wording per sponsor meets the consent standard in the Unsolicited Electronic Messages Act 2007 for the sponsor's messages, and whether we need to be more specific about channel (text versus email) per opt-in.

3.11 Shona, our AI host

Shona is an AI persona. When you chat with Shona on the site or by text, or ask her something in the app, your message and enough context to answer it are sent to one or more AI providers to generate the reply. Shona also writes the daily video script and reads out draw results, but those do not use your personal information beyond published winners (section 3.8).

What we send to AI providers: The text of your messages, your display name, your home region, and game facts relevant to the question (your score today, whether you have an entry, whether you won). We do not send your mobile number, email address, IP address or draw salt. Chats are logged so that a human can review Shona's answers and fix mistakes.

Who the providers are: Anthropic and OpenAI (text), ElevenLabs (voice). All three are based in the United States and process information overseas. Under their commercial terms, none of them uses our content to train their models. We treat these providers as our processors: they act on our instructions and for no purpose of their own. See section 5 on overseas processing.

Note for the lawyer: the ElevenLabs training opt-out must be set at account level, or an enterprise agreement used; confirm this has been done before launch so the "no training" statement is true.

What Shona does not do: Shona does not decide who wins (the public randomness beacon does), does not decide whether an entry is void (a person does), and cannot see your mobile number. If Shona gives you a wrong answer about a prize, the terms of entry and the published draw log prevail.

Text messages to Shona: If you text a question to our number, that text is handled the same way. Our gateway strips your number before the message goes to an AI provider.

3.12 Analytics, cookies and local storage

We use a small number of cookies and local storage entries on your device:

Name or kind Purpose Type Life
Device token Keeps you logged in Strictly necessary Until you log out or delete the account
Session and security tokens, Turnstile Protect the site from bots, verify that you are human Strictly necessary Session
Preferences (region, sound, theme, dismissed prompts) Remember your settings Functional Until cleared
Game state and offline cache (service worker) Make the app work as an installable app, and work through short outages Strictly necessary Until cleared
Analytics Count visits, pages and errors so we can fix problems Analytics See below

Analytics: We use [Cloudflare Web Analytics, which does not use cookies or fingerprint devices and does not track you across sites]. We do not use Google Analytics, Meta Pixel or any advertising or cross-site tracking. If we ever add an analytics tool that uses cookies, we will ask first and update this table. [PRODUCT: keep this true. If the team chooses a cookie-based analytics tool, this section and the consent flow must change before it ships.]

Social login buttons only contact Google, Meta or X when you tap them. We do not load their tracking scripts on other pages.

New Zealand has no separate cookie law; the Privacy Act's collection and notice rules apply. We take the view that the entries above are either necessary to run the service you asked for or clearly explained here.

Note for the lawyer: confirm that no cookie banner is required for this set, and that a notice in this policy plus the in-app prompts for location and push are sufficient under IPP3.

3.13 People at sponsor businesses

If you are a contact at a sponsor, we hold your name, role, business contact details, the agreement you signed, the prizes you committed, redemption and deal statistics, and the messages between us. We may have found your business details from a public source, such as your own website or a directory, before we first contacted you; when we do, we tell you where we got them in that first message. We use these details to run the sponsorship, report results to you, and, if you ask, to tell you about our other services. Every marketing email from us identifies us and has an unsubscribe.

3.14 Information we collect from other sources

Most of what we hold comes from you. Where it does not, this is where it comes from:

For each of these, this policy is our notice to you under IPP3A of the Privacy Act (which applies to information collected indirectly on or after 1 May 2026) of the fact of collection, its purpose, who receives it, who holds it and your rights. Where we collect something about you indirectly that this policy does not cover, we will tell you as soon as we reasonably can.

4. What we do not do

5. Where your information goes, and overseas processing

In New Zealand: Our SMS gateway and the My Shout number run on a server in New Zealand. Human review, sponsor management and Shona's back office run in New Zealand.

On Cloudflare's global network: The website, the game, the draw, our database and our public draw log run on Cloudflare (Cloudflare, Inc., United States). Cloudflare stores and processes information in data centres around the world, including in Australia and New Zealand, and serves the site from the location nearest to you. Cloudflare acts as our processor under its data processing terms and does not use our players' information for its own purposes. [PRODUCT: where Cloudflare offers it, pin player data to the Oceania region; note that Durable Object jurisdiction restrictions and location hints are best-effort or limited to certain regions, so do not promise NZ-only storage in public copy.]

AI providers: Anthropic, OpenAI and ElevenLabs (United States) process Shona chats as described in section 3.11.

Push and SMS delivery: Apple, Google and Mozilla push services deliver notifications to your device; backup SMS providers may deliver texts.

Number and fraud checks: [Provider(s)] as described in section 3.1.

How the Privacy Act applies: Under the Privacy Act 2020, when an overseas provider holds or processes information only on our behalf, for our purposes and under our instructions, it is treated as information held by us, and the disclosure rules (IPP12) do not apply, although we remain fully responsible for keeping it secure (IPP5). Each provider above is engaged on that basis, under written terms that restrict what it may do with your information. If we ever need to disclose your information to an overseas organisation for its own use, we will do so only where the Privacy Act allows it, which means with your express consent after telling you the recipient may not be bound by comparable privacy safeguards, or where the recipient is subject to comparable protections.

Note for the lawyer: (1) confirm the processor analysis for each provider, in particular the AI providers, given each retains logs for abuse monitoring for its own purposes (OpenAI states 30 days). If any provider is not purely an agent, IPP12 applies and we need the express consent route or contractual safeguards. (2) Confirm whether we should obtain a consent under IPP12(1)(a) at sign-up as a belt-and-braces measure, and if so, the wording.

6. Security

No system is perfectly secure. If we have a privacy breach that has caused, or is likely to cause, serious harm to anyone, we will notify the Office of the Privacy Commissioner as soon as practicable (the Commissioner expects within 72 hours) and notify the people affected, unless a lawful exception applies. We will tell you what happened, what we are doing about it and what you can do.

7. How long we keep things

We keep information only as long as we need it for the purpose we collected it. Working periods, all subject to lawyer review:

Information Kept for
Login codes 10 minutes, then deleted
Inbound and outbound SMS logs 90 days, then only the fact and time of delivery
IP addresses and location signals 90 days, longer only for accounts under fraud review
Gameplay answers and timings 12 months, then aggregated
Scores, streaks and leaderboard history While your account is open
Draw entries: your salt and the link between you and your leaves While your account is open; deleted on account deletion
Published draw log (leaves, roots, proofs) Permanent, and not personal information once the salt is deleted
Winner records (who won what, when it was claimed and redeemed) [3 years] after the draw, for Fair Trading and prize dispute purposes, then anonymised
Consent records While your account is open, then [2 years] as evidence of what was agreed
Sponsor opt-in records While the opt-in stands, then [2 years]
Shona chat logs 90 days, then deleted or anonymised
Redemption codes Until expiry plus 90 days, then anonymised
Sponsor contracts, invoices and financial records 7 years, as tax law requires
Fraud blocklist (hashed numbers and device fingerprints of banned accounts) [2 years] after the ban
Backups Rolled off within 30 days of deletion

Note for the lawyer: confirm each bracketed period. In particular: the winner record period, whether a hashed number can stay on a fraud blocklist after the rest of the account is deleted, and whether any Gambling Act or Fair Trading Act record-keeping period applies to promoters of free draws.

8. Your rights

Access and correction. You can ask us for a copy of the personal information we hold about you and ask us to correct it. Most of it you can see and change in My Account. For anything else, email privacy@myshout.nz. We will respond within 20 working days as the Privacy Act requires, and usually much sooner. If we decline to correct something we will attach your statement of the correction you asked for.

Deletion. You can delete your account in My Account, or ask us to. What is deleted, what is kept and why, and how the Google, Facebook and X routes work, is set out at myshout.nz/data-deletion.

Withdrawing consents. Push notifications, browser location, winner publication and every sponsor opt-in can each be withdrawn in My Account, separately, without closing your account.

Unsubscribing. Every marketing message from us or a sponsor tells you how to stop. Replying STOP to a text from us stops texts from us.

Complaints. Email privacy@myshout.nz first and we will try to fix it. If you are not satisfied you can complain to the Office of the Privacy Commissioner, privacy.org.nz, 0800 803 909.

9. Sponsors and other businesses

Sponsors are independent businesses. When you redeem a prize or a deal at a sponsor, anything you give them directly (for example, a booking name) is governed by their privacy policy, not ours. Deals may link to a sponsor's own website. We are not responsible for what sponsors do with information you give them, but we do require sponsors who receive opt-in details from us to use them only as section 3.10 describes, and we will act on complaints about a sponsor misusing them.

My Shout is not affiliated with, sponsored by or administered by Meta, Google, X, Apple or Cloudflare.

10. Changes to this policy

We will change this policy when the game changes. When we do we will update the version and date at the top, and for any change that expands what we collect or share we will ask you to agree again before it applies to you. Older versions are available on request.

11. Contact

NetPotential Limited, trading as Growth Spurt [POSTAL ADDRESS], Auckland, New Zealand privacy@myshout.nz [PHONE]

Our privacy officer is [NAME].

Note for the lawyer: confirm that naming a privacy officer is required (the Act requires every agency to have one) and whether the name should be published.

Terms · Competition terms · Privacy · Data deletion