Privacy Policy

Last updated: 29 August 2026

tiny.help is run by GoodSign Limited, a company incorporated in New Zealand. This policy explains what we collect, why, who else touches it, and what you can ask us to do about it. We have tried to write it in plain language and to describe what the software actually does, rather than everything a lawyer could imagine it might do.

On this page

  1. Two kinds of people
  2. What we collect
  3. Who is responsible for what
  4. How we use it
  5. AI and automated processing
  6. Who else touches your data
  7. Cookies
  8. How long we keep it
  9. Security
  10. Where your data lives
  11. Your rights
  12. If you chatted with a business
  13. Children
  14. If something goes wrong
  15. Changes
  16. Contact us

1. Two kinds of people

This policy covers two groups, and the difference matters throughout:

2. What we collect

2.1 From customers

2.2 From your visitors, on your behalf

When someone opens the chat widget on a customer’s site, we record:

Those last two points are worth stating plainly rather than burying: a visitor’s IP address, approximate city, and recent browsing history on that one site are visible to the business they chose to message. It is there so a support answer can be useful. It is not used to track anyone across the web, it is not sold, and it is not combined with data from other sites.

2.3 Automatically, on our own website

3. Who is responsible for what

In the language of the GDPR and the New Zealand Privacy Act 2020:

If you run a desk on tiny.help, that makes you responsible for having a lawful basis to collect what your visitors send you, and for telling them about it in your own privacy policy. We give you the tools; the relationship with your visitors is yours.

4. How we use it

We do not sell personal information. We do not share it with advertisers. We do not use conversation content to build advertising profiles.

5. AI and automated processing

There are two separate ways AI can touch a conversation, and they are worth keeping apart.

5.1 AI tools you connect yourself

You can connect your own AI tools to your desk — through our MCP integration or through our API — using your own accounts with those providers. When you do, the conversation content your tool requests is sent to the provider you chose, and is processed under your agreement with them, not ours. That processing happens on their systems, we do not control it, and their terms and privacy policy govern what they do with it.

These connections are yours to manage. One exists only after you set it up, you decide which tools get access and what they can reach, and you can revoke that access at any time from your account.

5.2 AI we use to run the service

We may use third-party AI services to provide and improve features such as drafting replies, summarising conversations, or classifying and routing messages. Where we do, conversation content may be sent to those providers, who act as our sub-processors and handle it under contract with us. Any provider we use in this way will be named in section 6 before it starts processing customer data.

5.3 What we do not do

We do not sell personal information. We do not use your conversations to train our own models, and where we engage an AI provider we do so on terms that do not permit them to train their models on your content.

No AI-generated message reaches one of your customers on its own. Drafts are drafts, and a person approves them before they are sent.

6. Who else touches your data

We keep the list of sub-processors short on purpose. In full, it is:

We may also disclose information where the law requires it — a court order, a lawful request from an authority — or to investigate abuse of the service. If we are ever bought or merged, your data may transfer with the business, subject to this policy.

7. Cookies

We use as few as we can:

There are no advertising cookies and no third-party tracking cookies. Our analytics are cookieless.

8. How long we keep it

Being accurate about this matters more than sounding reassuring:

If you close your account, ask us and we will delete your data. If you need particular conversations or a particular visitor’s record removed sooner, ask — see section 11.

9. Security

Traffic is encrypted in transit, and data is encrypted at rest by our infrastructure provider. Access is limited to the people who need it to operate the service. Each account’s data is isolated from every other account’s.

No system is perfectly secure, and we would rather say so than imply otherwise. Use a real password manager, and tell us straight away if you think your account has been reached by someone else.

10. Where your data lives

Our application runs on Cloudflare’s global network, so requests are served from wherever the visitor is. The primary database is located in Oceania. Backups and replicas may sit in other regions, and our sub-processors operate internationally — so your data may be processed outside your own country. Where that happens, we rely on the safeguards those providers offer, including standard contractual clauses.

11. Your rights

Depending on where you live, you can ask us to:

Email hey@tiny.help and we will respond within 20 working days, which is what the New Zealand Privacy Act requires. There is no charge.

If you are in the EU or UK and you are unhappy with our answer, you can complain to your local data protection authority. In New Zealand, you can complain to the Office of the Privacy Commissioner.

12. If you chatted with a business

If you used a chat widget on someone’s website and want your messages removed, the business you were talking to controls that data, so they are the fastest route — they can delete the conversation themselves.

You are welcome to contact us directly at hey@tiny.help and we will help, either by acting on the customer’s instruction or by putting you in touch with them.

13. Children

tiny.help is a business tool and is not intended for children under 16. We do not knowingly collect their personal information. If you believe a child’s information has reached us, tell us and we will delete it.

14. If something goes wrong

If there is a breach that is likely to cause anyone serious harm, we will notify the Office of the Privacy Commissioner and any other regulator we are required to tell — within 72 hours where the GDPR applies — and we will tell the people affected without undue delay, along with what we know and what to do about it.

15. Changes

We will update this page when the service changes. If a change materially affects you, we will email you rather than quietly editing the page. The date at the top always reflects the current version.

16. Contact us

Questions about this policy, or a request about your data:

GoodSign Limited
2 Stuart Street, Ponsonby
Auckland 1011, New Zealand
hey@tiny.help

Or just — it reaches the same people.