SimpleONE Ops

SimpleONE Privacy Policy

Effective 10 September 2026

Who we are and what SimpleONE does

SimpleONE (also called SimpleONE Ops) is operated by Digital Simple Limited, New Zealand. It is our internal application for managing client relationships and delivering marketing, advertising, reporting and related business services to our clients.

SimpleONE is primarily used by authorised Digital Simple staff. Clients and their representatives may receive reports, invoices, approval requests or other selected information through the services we provide. It is not a public advertising network or a marketplace for personal information.

This policy explains how we handle personal information in SimpleONE. It covers staff users, client representatives and people whose information is supplied through our clients or their authorised systems. Our clients remain responsible for explaining their own collection and use of customer information, including notices on their websites and forms.

Information we collect

The information available depends on the services a client uses and the systems they authorise us to access. It may include:

We receive information from staff, clients and their representatives, authorised connected services, and interactions with SimpleONE or client services connected to it. Public business information may also support research and campaign planning.

How we use information

We use information to deliver and administer the services agreed with our clients. This includes managing client relationships; planning and operating authorised advertising; monitoring budgets; producing performance reports; reconciling advertising costs; calculating agreed fees; preparing invoices; handling enquiries and approvals; and supporting staff workflows.

We also use relevant information to maintain the application, manage access, investigate errors, protect information and keep appropriate business and audit records. We do not sell personal information.

Where AI-assisted features are used, relevant business information or communications may be processed by configured AI service providers to support research, drafting, summaries or classifications. These outputs may be incomplete or inaccurate and support staff work rather than replacing responsibility for decisions. The information processed depends on the enabled feature and its configuration.

Connected accounts and advertising platforms

Connections operate using the permissions granted by an authorised account holder or administrator. Depending on the service, SimpleONE may connect to advertising, analytics, CRM, email, accounting or other business systems, including Google, Meta, HubSpot, Xero and related service providers.

Pinterest and LinkedIn reporting connections are being introduced for authorised advertising account and campaign data, initially to reconcile spend and prepare client invoices. Their intended reporting use does not require access to private member messages or personal social profiles. A connection is available only after the relevant implementation, platform approval and account authorisation are complete.

Reporting access does not itself authorise us to change campaigns. Any campaign management supported by other integrations is subject to the applicable permissions and client service arrangements.

You can withdraw connected-account access through the platform's permission settings or ask us to disconnect it. This may prevent continued reporting or other dependent services. Revoking access does not automatically delete records previously collected; retention and deletion are addressed below.

Who can receive information

Information may be accessed by authorised staff and service providers where needed to operate SimpleONE or deliver client services. These include hosting and database providers such as Vercel and Supabase, connected business platforms, communications services and configured AI providers.

We may provide relevant reports, invoices and service information to the client and their authorised recipients. Some reports or approval pages can be shared by link; recipients should treat these links as confidential and avoid forwarding them beyond the intended audience.

We may also disclose information where required or permitted by law, or where necessary to obtain professional advice or address a security incident. Connected platforms handle information under their own policies as well as the permissions and arrangements governing our use of them.

Storage and protection

SimpleONE uses authentication, role and workspace access controls, and protected server-side handling of connection credentials. No online system can guarantee absolute security.

Our technology providers may store or process information outside New Zealand. Where overseas disclosure is subject to New Zealand privacy requirements, we must ensure an applicable legal basis or appropriate safeguards. Contact us for information about providers relevant to your service.

Retention and deletion

We retain information for the purposes described in this policy, including delivering services, maintaining financial and audit records, resolving disputes and meeting legal obligations. The necessary period varies by the type of information and the service involved.

You may request deletion of personal information or data associated with a connected account. We will assess the request and explain any information that must be retained and why. Disconnecting an account, ending a service or requesting deletion does not necessarily remove records held independently by the original platform. Backup copies may remain until the applicable backup lifecycle expires.

Cookies and sessions

SimpleONE uses cookies or similar browser storage where needed for sign-in, sessions and application operation. Disabling these may prevent parts of the application from working. Connected platforms may use their own cookies under their policies.

Your choices and rights

You can ask to access or correct personal information we hold about you. We may verify your identity and authority before providing information. If we decline a correction, you can ask for a statement of the correction sought to be attached to the record. You can also raise concerns about collection, use, sharing or retention.

Providing information or authorising an integration is generally voluntary, but without information necessary for a service we may be unable to provide it. Where information is held on a client's behalf, we may need to coordinate your request with that client.

If you are not satisfied with our response to a privacy concern, you can contact the New Zealand Office of the Privacy Commissioner.

Contact us

For privacy questions, access or correction requests, or requests to disconnect or delete connected-account data, contact Digital Simple Limited at social@digitalsimple.co.nz, with the subject SimpleONE privacy request. Include enough information to identify the relevant account or service, but do not send passwords or access tokens.

Postal/contact address: Digital Simple Limited, 360 Tuam Street, Christchurch, New Zealand.

Changes to this policy

We may update this policy when our services or information practices change. The published version will show its effective or last-updated date. Material changes will be communicated to affected users or clients where appropriate.