Sucess
Ramsys Privacy, Customer Data Ownership & Data Sovereignty Policy
Last updated: 15 September 2026
1. About this policy
Allspoke Ltd ("Allspoke", "we", "us" or "our") provides Ramsys, a business management platform supporting retail, hospitality and service-based organisations. Ramsys provides point-of-sale, customer management, inventory, ecommerce, service management, loyalty, reporting, accounting integration, operational management and related functionality.
This policy explains how information processed through Ramsys is owned, collected, used, stored, protected and managed. It applies to:
- Ramsys core platform (POS, inventory, ecommerce, loyalty, reporting)
- Ramsys's integration with Shopify
- The Ramsys Digital WoF Check Sheet service, provided to NZTA-approved vehicle Inspecting Organisations (IOs)
Ramsys is based in New Zealand and currently provides services to New Zealand customers. Ramsys production data is hosted in New Zealand. Protection of customer data, customer ownership and New Zealand data sovereignty are fundamental principles of the Ramsys service.
2. Customer Data Ownership
The customer owns its data wholly and without exception. All business and operational data entered into, generated by, imported into or processed through Ramsys on behalf of a customer remains the property of that customer. Allspoke does not acquire any ownership, proprietary interest or commercial right in customer data by virtue of providing the Ramsys service.
This includes, without limitation:
-
Customer and client records
-
Sales and transaction information
-
Product and service information
-
Inventory and stock information
-
Supplier information
-
Staff and operational information
-
Loyalty information
-
E-commerce information
-
Service and job information
-
Vehicle inspection and WoF check sheet records (Section 8)
-
Reporting and analytical information
-
Accounting-related information
Information received from systems integrated with Ramsys (including Shopify and the NZTA Motor Vehicle Register API)
Any other business data stored or processed through Ramsys on behalf of the customer
Allspoke acts solely as the provider and custodian of the Ramsys platform and, where personal information is involved, as a processor of that information on behalf of the customer, except where Allspoke has an independent legal obligation (for example, direct notification obligations to NZTA).
Allspoke will not sell, trade, licence, monetise or otherwise commercially exploit customer data. Allspoke will not use one customer's data for the benefit of another customer. Customer data will not be used to create marketing databases, advertising profiles or other commercial datasets belonging to Allspoke or any third party.
3. New Zealand Data Sovereignty
Ramsys data sovereignty is based in New Zealand. Ramsys production data hosted by Allspoke is stored on infrastructure located within New Zealand, provided through New Zealand-based infrastructure and service providers.
Ramsys does not intentionally transfer its hosted customer databases to overseas hosting environments for storage or processing as part of the normal operation of the Ramsys service. Allspoke currently has no international Ramsys customers and does not operate Ramsys production hosting infrastructure outside New Zealand.
Where a customer specifically authorises Ramsys to integrate with an external service (for example, Shopify, accounting, marketing, payment or communications platforms selected by the customer), information may be transmitted to that service as necessary to provide the requested functionality. Such transmission is performed at the customer's direction and does not alter Allspoke's commitment that the Ramsys-hosted copy of the customer's production data remains hosted in New Zealand. External services selected by the customer may store or process information outside New Zealand and are governed by their own terms and privacy policies.
4. Personal Information We Collect
The categories of personal information Ramsys processes depend on which services a customer uses.
Core Ramsys platform:
-
Customer/client name, contact details, purchase history, loyalty account information
-
Staff names, login credentials, and role/access data
-
Payment tokens processed via the customer's chosen payment provider (Ramsys does not store full card numbers)
Shopify-connected stores:
-
Shopify customer order, contact and fulfilment data, limited to what is required to deliver the connected functionality
WoF Digital Check Sheet service:
-
Vehicle registration details (rego, VIN, make, model, year) retrieved via the NZTA Motor Vehicle Register API
-
Vehicle owner/customer contact details — not retrieved from NZTA; sourced either from the Inspecting Organisation's own customer records (e.g. via InfoAgent at point of sale) or entered manually by inspection staff
-
Vehicle inspector name, authority/licence number, and inspection sign-off
-
Inspection results, measurements, pass/fail data, and rejection reasons
-
Photographs of the vehicle, where the Inspecting Organisation enables this optional feature
-
Device location (GPS) data from the mobile device used to submit an inspection, where the service is accessed via a mobile application
5. How We Use Information
Information is used only to provide, maintain, secure and support the Ramsys service the customer has engaged Allspoke to deliver, including:
-
Operating the specific Ramsys feature or module the customer is using
-
Submitting WoF inspection results to NZTA on the customer's behalf, where the customer uses the WoF service
-
Detecting fraud, misuse and security incidents
-
Complying with legal and regulatory obligations, including those imposed by NZTA and the Privacy Act 2020
6. Shopify Integration and Protected Customer Data
Where a customer connects Ramsys to their Shopify store, Ramsys accesses Shopify customer data only to the extent necessary to deliver the specific integration functionality the customer has enabled (for example, syncing orders, inventory or customer records). Ramsys does not use Shopify customer data for any other purpose, does not sell or share it with third parties, and does not use it to build profiles unrelated to the customer's own store.
On disconnection or uninstallation of the Ramsys–Shopify integration, Shopify customer data held by Ramsys is deleted in accordance with Shopify's API License and Terms of Service and applicable data retention requirements
7. WoF Digital Check Sheet Service — NZTA-Specific Terms
This section applies specifically to the Ramsys Digital WoF Check Sheet service used by NZTA-approved Inspecting Organisations (IOs), and is designed to meet NZTA's Appendix 1 Information Governance requirements for digital check sheet providers.
7.1 Design compliance
The WoF Digital Check Sheet service is designed to comply with the Privacy Act 2020 in respect of any personal information it collects, processes or stores, including vehicle owner/customer details entered by an IO, inspector identity data, and any photographs or location data captured during an inspection.
7.2 Location data
Where the service is accessed via a mobile application, GPS location data is collected from the device at the time an inspection is submitted, as required by NZTA. This is used solely for inspection integrity and fraud-detection purposes (Section 8.4) and is not used for any other purpose, including marketing or profiling.
7.3 Data retention and deletion
- A copy of each submitted electronic check sheet is retained and immediately retrievable for a minimum of 12 months.
- Audit and security event logs relating to the service are retained for a minimum of 12 months and protected from tampering or deletion.
- Vehicle inspection data is automatically deleted from mobile applications on end-user devices once it has been uploaded to Ramsys's server-side data repositories.
- Vehicle inspection data is automatically deleted from any intermediate transfer location (such as a web form) once uploaded to server-side repositories.
7.4 Fraud and misuse monitoring
Ramsys monitors inspection activity for patterns indicating possible fraud or credential misuse, including but not limited to: an inspector ID used in different locations during overlapping times, inspections in areas without a local IO, unusually high inspection volumes in short periods, abnormal vehicle lookups with no inspection submitted, unexpected changes to inspection records, and inspections outside normal business hours.
7.5 Inspecting Organisation responsibilities
Each Inspecting Organisation using the WoF Digital Check Sheet service is notified of its own obligations under the Privacy Act 2020 in relation to personal information it enters into or manages through the service (including vehicle owner/customer contact details it sources itself), and is required to formally acknowledge this responsibility under its service subscriber agreement with Allspoke. IOs must notify Allspoke of any suspected or confirmed breach involving information processed through the service.
7.6 Breach notification
Allspoke will notify affected individuals and the Office of the Privacy Commissioner in accordance with the mandatory breach notification requirements of the Privacy Act 2020. In addition, Allspoke will notify NZTA's Security Operations team of any suspected or confirmed security incident affecting the confidentiality or integrity of vehicle inspection records, as required under NZTA's digital check sheet provider security requirements.
7.7 What NZTA does with information in this application
Information Allspoke submits to NZTA as part of the digital check sheet provider application process is held by NZTA and treated as confidential subject to the Official Information Act 1982 and Privacy Act 2020. Individuals named in the application are entitled to access and request correction of their own personal information held by NZTA, by writing to Private Bag 11777, Palmerston North 4442, or emailing info@nzta.govt.nz.
8. Data Security
Cryptographic protection is applied to vehicle inspection and customer data in transit and at rest. Access to production data is restricted to authorised Allspoke staff on a role-based, least-privilege basis, and all Allspoke staff are bound by confidentiality obligations. `[CONFIRM: specific controls actually in place — encryption standard, MFA, access logging, any current certifications — before this is used as assurance evidence for NZTA or Shopify. A general statement here without matching technical controls behind it is a compliance risk, not a formality.]`
9. Your Rights
Individuals may request access to, or correction of, their own personal information held by Ramsys by contacting `[CONFIRM: named role/email — e.g. privacy@allspoke.nz]`. Requests relating to information held by a specific Ramsys customer (retailer or IO) should first be directed to that business, as they are the data owner under Section 2.
10. Changes to This Policy
Where this policy changes in a way that affects how personal information is handled, customers will be notified via email before the change takes effect.
10. Contact
Allspoke Ltd, 20a Vale Road, Whangarei. Email: support@allspoke.com.


_edited_edited.png)
.png)