Privacy notice
What we collect, why we need it, who may receive it, how long we keep it and the requests you can make.
MarryNZ is a trading name of Photonmark Limited (NZBN 9429046103741). Photonmark Limited is the New Zealand agency that collects and holds the information described here. The company and registered-address details are available in the official NZBN record. Privacy enquiries, requests and complaints: [email protected].
Before a material change to the stated purposes, access scope or retention period applies to an existing applicant, we will give notice through the account or verified email and seek fresh confirmation where the law requires it.
You may access your information and ask us to correct it. If we do not make a requested correction, you may ask us to attach your correction statement. Use your account or email [email protected] from your registered address; we respond to access and correction requests within 20 working days unless a lawful extension applies. You may complain to the New Zealand Privacy Commissioner if a privacy concern is not resolved.
What we collect and why
We collect account and contact details; application, lifestyle, current height and weight, and partner-preference information; identity, photo, ordinary-residence and any optional supporting evidence; payment, GST and receipt information; communications, meeting notes and feedback; and necessary session, device, security and access-audit records. We use them only as reasonably necessary to operate and secure accounts, contact applicants, review and verify applications, prevent impersonation or fraud, provide contracted human matchmaking, process payments and tax records, handle safety concerns or disputes, and meet legal obligations.
Providing information is voluntary, but fields marked as required and the stated ordinary-residence evidence are needed to submit an application. Identity evidence and the required photos are needed no later than two business days before the formal interview. If necessary information is not supplied, we may be unable to review, verify, contract with, introduce or provide the requested pricing category to the applicant. Optional evidence is not required merely because the upload field exists.
Most information comes directly from the applicant. We may also obtain information that is directly relevant to verification, payment, safety or introduction feedback from an applicant-nominated person, an official or verification source, a payment provider, or the other participant in a specific introduction. Where that creates personal information about you, we will take reasonable steps to tell you about the collection, purpose and intended recipients as soon as reasonably practicable, unless a Privacy Act exception applies. The site uses an essential sign-in cookie and stores the selected language in the browser; servers also create necessary security and access records.
Access and private sharing
Access is limited to authorised staff who need the relevant information for review, matching, safety, support or technical maintenance, and to contracted hosting, file-storage, email and payment providers for their stated tasks. We do not sell member information or provide a searchable public member directory.
Application information is private. The full application enters the protected private candidate pool only after the membership agreement is signed and membership payment is confirmed. Green-marked fields form a privacy-safe draft summary, including current height and weight and any stated height or weight preferences, but the member sees and approves the exact content before each one-to-one share for a specific proposed match. Identity files, document numbers, full name, date of birth, private contact details, health information, religion, review notes, and ordinary-residence or GST evidence are excluded.
Private contact details are not exchanged before both people agree. If a member asks for an independent professional or practical-service referral, we first identify the provider, purpose and exact information proposed for sharing, then send only what is necessary after express permission.
Overseas processing
Contracted providers store or process the website, application database, encrypted private uploads, account and service email, and necessary payment information outside New Zealand. Hosting, file and email processors must act for the contracted operational and security purposes. Payment providers receive only the payer email, billing name and address or country, internal customer and order reference, amount, payment method, device and fraud-prevention information needed for checkout; they do not receive the application, photos or identity evidence, and Photonmark does not store full card numbers or Alipay credentials. A current provider list is available from the privacy contact.
A provider acting only on our behalf for storage or processing is treated under section 11 of the Privacy Act as our agent, and Photonmark remains responsible for that information. Providers may use information only for the contracted service, security, payment, fraud-prevention and legal-compliance purposes applicable to their role; they may not sell it or use it for unrelated advertising.
If an overseas recipient will use or disclose information for its own purposes, we disclose only where Privacy Principle 11 permits and Principle 12 is satisfied through New Zealand coverage, comparable safeguards, an appropriate agreement, or genuinely informed authorisation. Overseas processing does not waive New Zealand privacy rights.
Retention, security and deletion
Text drafts and encrypted upload drafts expire 30 days after the last update unless formally submitted. Original identity, photo, ordinary-residence and supporting files are kept while needed for an active application or membership and are normally deleted within 12 months after rejection, withdrawal or the end of service. Earlier deletion may be requested when an original is no longer needed.
After an original is deleted, necessary file type and hash records, verification results, consent versions, approved-summary versions and access-audit evidence are normally kept for no more than six years after the application or service ends, or after a related complaint or dispute is finally resolved if later. They are kept longer only while an active account purpose, safety matter, legal hold or statutory record duty makes that reasonably necessary. Financial and tax records may be kept separately for seven years. Live deletion is followed by expiry from encrypted backups within the 35-day rotation.
We use access controls, encryption for protected uploads, random storage names and access auditing, and we review retention needs rather than keeping originals indefinitely. If a privacy breach has caused or is likely to cause serious harm, we will notify the Privacy Commissioner and affected people as soon as practicable as required by law.