Privacy Policy.
Last Updated: 5 June 2026
TerraMind Limited ("TerraMind", "we", "us", "our") operates the TerraMind platform at terramind.co.nz. This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with the New Zealand Privacy Act 2020.
1. Information we collect
1.1 Account information
When you create a TerraMind account, we collect:
- Full name
- Email address
- Phone number (optional, for SMS alerts)
- Password (managed by our authentication provider, Clerk)
1.2 Orchard and block data
When you set up your growing operation, we collect:
- Orchard name and address
- Block boundaries (geographic polygons drawn or confirmed by you)
- Crop type, variety, and planting year per block
- Protection action cost assumptions (e.g., wind machine cost, frost cloth cost)
1.3 Management action records
When you log management actions, we collect:
- Action type, date, cost, and block
- Decision records (which recommended action you chose)
1.4 Financial data (Xero integration)
If you connect your Xero account, we receive read-only access to:
- Revenue and expense records
- Account categories and transaction details
- Supplier invoices relevant to orchard operations
We do not store your Xero credentials. Authentication uses OAuth 2.0 tokens managed securely.
1.5 Usage data
We collect standard usage information:
- Pages visited and features used
- Device type and browser
- IP address and approximate location
- Session duration and interaction patterns
1.6 Data we derive
From your orchard data and public data sources, we derive:
- Elevation, slope, aspect, and soil type for your blocks (from LINZ and Smap)
- Satellite vegetation indices (NDVI from Sentinel-2 / Copernicus)
- Weather observations and forecasts attributed to your blocks (from NIWA, Open-Meteo, MetService)
- Probabilistic predictions (frost risk, disease pressure, yield trajectory, irrigation need)
- Financial projections (expected revenue, losses, cash flow)
2. How we use your information
We use your information to:
- Provide the TerraMind service — generate predictions, financial projections, and recommendations for your orchard
- Send alerts — SMS and email notifications when prediction thresholds are breached or decisions are recommended
- Improve our models — use de-identified, aggregated data across all users to improve prediction accuracy and calibration
- Communicate with you — service updates, onboarding guidance, and support
- Maintain security — detect and prevent unauthorised access or abuse
We do not sell your personal information. We do not use your data for advertising.
3. Legal basis for processing
Under the New Zealand Privacy Act 2020, we collect and process your information because:
- It is necessary to provide the TerraMind service you requested (Information Privacy Principle 1)
- Collection is directly from you or with your knowledge (IPP 2 and 3)
- We use it only for the purposes described in this policy (IPP 10)
4. Who we share your information with
We share your information only with:
| Recipient | Purpose | Data shared |
|---|---|---|
| Clerk (authentication) | Account management and login | Name, email, auth tokens |
| Twilio (SMS) | Alert delivery | Phone number, alert content |
| Resend (email) | Alert and notification delivery | Email address, alert content |
| Neon (database hosting) | Data storage | All service data (encrypted at rest) |
| Railway (compute hosting) | Service execution | Processed in memory only |
| Vercel (web hosting) | Frontend delivery | Standard web request data |
| Sentry (error tracking) | Bug detection and resolution | Error context (no personal data by design) |
| Axiom (logging) | Operational monitoring | Service logs (minimised personal data) |
| OpenRouter (AI provider) | Ask TerraMind reasoning | Block context for LLM queries (no PII) |
| Xero (if connected) | Financial data sync | OAuth tokens only; Xero sends data to us |
We do not share your orchard data, predictions, or financial information with any third party for their own purposes. We do not share data with insurers, banks, industry bodies, or government agencies unless you explicitly consent or we are required by law.
5. Data retention
- Account data is retained while your account is active and for 12 months after deletion to allow account recovery
- Orchard and prediction data is retained while your account is active. On account deletion, your identifiable data is deleted within 30 days; de-identified aggregated data used for model calibration is retained
- Alert delivery records are retained for 24 months for audit and debugging purposes
- Xero data is deleted when you disconnect the integration or delete your account
6. Your rights
Under the Privacy Act 2020, you have the right to:
- Access your personal information — request a copy of all data we hold about you
- Correct inaccurate information — update your details at any time through the account settings or by contacting us
- Export your data — use the data export feature in your account to download your orchard profile, blocks, management actions, predictions, and financial data in JSON format
- Delete your account — contact us to request account deletion; we will delete your identifiable data within 30 days
To exercise any of these rights, email privacy@terramind.co.nz.
7. Data security
We protect your information with:
- Encryption in transit (TLS/HTTPS on all connections)
- Encryption at rest (Neon database encryption)
- Role-based access control within orchards (Owner, Manager, Viewer)
- JWT-based authentication with secure session management
- No plaintext storage of passwords or API keys
- Admin access is logged and visibly indicated in the interface
8. Cookies
TerraMind uses essential cookies for authentication and session management. We do not use tracking cookies or third-party advertising cookies. If we introduce analytics in the future, we will update this policy and obtain your consent where required.
9. International data transfers
Your data is processed on servers in the United States (Railway, Vercel, Neon) and may transit through other jurisdictions. We ensure all service providers maintain appropriate security standards. New Zealand's Privacy Act 2020 requires that personal information transferred overseas receives comparable protection.
10. Children's privacy
TerraMind is a professional agricultural tool and is not directed at children under 16. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address on your account and noted on this page with an updated effective date. Continued use of the service after changes constitutes acceptance.
12. Contact us
If you have questions about this Privacy Policy or wish to exercise your rights:
- Email: privacy@terramind.co.nz
- Mail: TerraMind Limited, 368 Blockhouse Bay Rd, Auckland 0600
If you are not satisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner at privacy.org.nz.