Privacy policy
Te Awa Ventures Limited (NZBN 9429052881329), trading as PowderFactor ("PowderFactor", "we", "us") is a New Zealand company that makes software for drill and blast crews. This policy explains what personal information we collect through the PowderFactor Field mobile app (the "App"), the PowderFactor Field office portal (the "Portal") and this website, why we collect it, who we share it with and the choices you have.
We handle personal information in line with the New Zealand Privacy Act 2020 and, for our Australian customers, the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where the two differ we apply the stricter standard.
1. Two roles: your employer's data and ours
Most information in the App and the Portal is entered by, and belongs to, the organisation that uses Field (usually your employer or the contractor you work for). That organisation decides who is added, what is recorded and how long it is kept, and we hold the information on its behalf. If you are a crew member with a question about a record about you, your organisation's Field administrator is the first place to ask; we will help them respond.
Information you give us directly, for example through the request-access form on this website or by emailing support, is information we hold for our own purposes.
2. What we collect
2.1 In the App and the Portal (held for your organisation)
| Information | Where it comes from | Why |
|---|---|---|
| Your profile: name, work email, roles (for example driller, fitter, supervisor), licences and competencies with their expiry dates, and whether your account is active | Entered by your organisation's administrator in the Portal | So you can be identified on records you create, and so your organisation can track who is qualified and licensed to operate what |
| Sign-in credentials: a personal PIN for the App (stored only as a one-way hash, never in plain text) and, for portal users, a Firebase Authentication account with an email address and password (stored by Google, never visible to us) | Generated by the Portal; you change your PIN or password yourself | To sign you in and to attribute records to you |
| Operational records: pre-start inspections, daily logs, drill logs, defects, maintenance and service records, training pass-outs and job packs, including the date and time, the rig or vehicle, the blast or site, and your name or ID as the person who completed or signed the record | Entered by you or your colleagues on a tablet, or by your organisation in the Portal | This is the purpose of the product: a record of the work your organisation does and who did it, kept for safety, maintenance and regulatory compliance |
| Photos and files attached to records, for example a photo of a defect | Taken with the tablet camera or chosen from its gallery by you | To document the condition of equipment and the work done. The App asks for camera permission only when you take a photo; it does not access photos you have not chosen |
| Sign-in activity: the time of each App sign-in attempt, whether it succeeded, the tablet's device identifier, and the rig and blast selected | Recorded by the App when you sign in | So your organisation can see who was signed in on which rig, and to detect misuse of a PIN |
The App does not collect your device's location, your contacts, or any information from other apps.
2.2 Diagnostics and usage data (held by us)
The App sends crash reports and basic usage analytics to Google's Firebase services (Firebase Crashlytics and Google Analytics for Firebase). A crash report contains the state of the App at the moment it failed, the device model and operating system version, and an installation identifier; it does not contain the contents of your records. Usage analytics tell us which screens are used and how often, so we can improve the App. This data is not used for advertising and we do not sell it.
2.3 On this website (held by us)
- Request-access and contact forms: the name, company, email, phone, country, fleet size and message you give us, plus the time of the request. We use these to respond to you and to set up your organisation.
- Server logs: our hosting provider, Cloudflare, records the IP address, browser type and pages requested for each visit, which we use for security and to keep the site running. Fonts are loaded from Google Fonts, which means your browser sends your IP address to Google when the page loads.
- We do not use advertising cookies or third-party tracking on this website.
2.4 Cookies and local storage
The Portal keeps your sign-in session, your light-or-dark theme choice and (for platform administrators) the organisation you are viewing in your browser's local storage. These are needed for the Portal to work and are not used to track you across other sites. The App keeps your records on the tablet so that it works offline, and syncs them when a connection is available.
3. How we use information
We use personal information to provide and support Field, to keep it secure, to fix problems, to communicate with our customers about their service, and to meet our legal obligations. If we ever want to use information for a new purpose that you would not reasonably expect, we will ask first.
We do not sell personal information, and we do not use the contents of your organisation's records to train any machine-learning model.
4. Who we share it with
We share information only with the service providers we need to run Field, each of which may only use it to provide their service to us:
- Google (Firebase and Google Cloud): hosts the database, file storage, authentication and crash reporting for the App and the Portal. Data is stored in Google Cloud data centres under Google's data-processing terms.
- Cloudflare: serves the Portal and this website and protects them from attack.
- Resend: sends transactional email on our behalf, such as a temporary PIN or a portal invitation.
- Apple and Google: distribute the App through the App Store and Google Play and provide their own crash and review data to us under their terms.
We may also disclose information where the law requires it, for example to a workplace safety regulator with the authority to request records, or to a professional adviser under a duty of confidence. We will tell the affected organisation unless we are legally prevented from doing so.
Some of these providers store information outside New Zealand and Australia. Where they do, we rely on their contractual commitments to protect it to a standard comparable with the Privacy Act 2020.
5. How long we keep it
Your organisation's records are kept for as long as it has a Field account, because safety and maintenance records are usually required to be retained for several years. When an organisation ends its subscription we provide a full export on request and delete its data 90 days after the account closes, except where we are required by law to keep it longer. Backups are overwritten on a rolling schedule within a further 30 days.
Crash reports and usage analytics are kept by Google for the retention period set in Firebase (90 days for crash reports; 14 months for analytics). Website form submissions are kept for up to 12 months after our last contact with you.
6. Security
All connections use TLS. PINs are stored only as one-way hashes; passwords are managed by Google's Firebase Authentication and are never visible to us. Access to your organisation's data in the Portal is limited by role, and every privileged operation runs on our servers rather than in the browser. PINs and other credential material are never included in any export. We review access to production systems and keep the number of people with that access to a minimum (currently the two founders).
If we become aware of a privacy breach that is likely to cause serious harm, we will notify the affected organisation and the Office of the Privacy Commissioner (New Zealand) or the OAIC (Australia) as the law requires.
7. Your rights
You have the right to ask for a copy of the personal information we hold about you and to ask us to correct it. If the information belongs to your organisation, we will work with its administrator to respond. You can also ask us to delete your account or information; see Delete your account or data for how, and for the limits that apply to safety records your organisation must keep.
To make a request, email privacy@powderfactor.com. We will respond within 20 working days. If you are not satisfied with our response you can complain to the Office of the Privacy Commissioner in New Zealand or the Office of the Australian Information Commissioner.
8. Children
Field is a workplace tool. It is not directed at children, and we do not knowingly collect information from anyone under 16.
9. Changes to this policy
We will post any changes here and update the date at the top. If a change materially affects how we use personal information, we will email our customers' administrators before it takes effect.
10. Contact
Te Awa Ventures Limited, trading as PowderFactor · NZBN 9429052881329
4 Te Awa Rere Grove, Stokes Valley, Lower Hutt 5019, New Zealand
Privacy: privacy@powderfactor.com · Support: support@powderfactor.com