Privacy Policy

Vila Mourisca Ltd trading as The Hotel Sheet
Last updated: 22 April 2026
Effective from: 22 April 2026


1. About This Policy

This privacy policy explains how Vila Mourisca Ltd, trading as The Hotel Sheet ("we," "us," "our"), collects, uses, stores, discloses, and protects your personal information when you visit our website (thehotelsheet.co.nz), place an order, create an account, sign up for marketing communications, leave a review, or otherwise interact with us.

We comply with the Privacy Act 2020 (New Zealand), the Information Privacy Principles ("IPPs"), the Unsolicited Electronic Messages Act 2007, and all other applicable New Zealand legislation.

Contact us:
Vila Mourisca Ltd t/a The Hotel Sheet
PO Box 68-578 Victoria Street West, Auckland 1145, New Zealand
Email: privacy@thehotelsheet.co.nz


2. What We Collect and Why

We collect personal information in two ways: directly from you, and indirectly through technology on our website.

Information you give us

When you place an order, create an account, contact us, or leave a review, you provide information such as your name, email address, postal address, phone number, payment details, and the content of your messages or reviews. We use this to fulfil your orders, manage your account, respond to enquiries, handle returns, send you marketing (with your consent), and meet our legal obligations including tax record-keeping.

Information collected automatically

When you visit our website, our technology partners collect information about your browsing behaviour. Under the Privacy Act 2020, we are required to tell you about this indirect collection:

  • Analytics: Google Analytics and Microsoft Clarity collect data about how visitors use our site (pages viewed, clicks, scrolling, session duration, device and browser information, general location). This helps us improve the website experience. Google Analytics uses cookies to distinguish visitors. Microsoft Clarity records browsing sessions and operates as an independent data controller for the data it collects.
  • Email tracking: Klaviyo, our email platform, tracks which pages you browse on our site and whether you open or click links in our emails. This is linked to your email address if you are a subscriber or customer.
  • Advertising: Meta (Facebook/Instagram) and Google Ads place tracking pixels and cookies on our site to measure advertising effectiveness and build audiences. These tools collect device information, browsing behaviour, and purchase events. Hashed (encrypted) versions of your email address may be shared with these platforms for audience matching.
  • Platform data: Shopify, our ecommerce platform, processes your customer record including name, address, email, phone, order history, and browsing behaviour. Shopify also facilitates payment processing — we do not store full credit card numbers.

It's worth noting that if you have a personal Facebook, Instagram, or Google account, those companies separately collect data about your activity across the internet, not just on a single website. Our data collection is limited to your activity on our site and your direct interactions with us.


3. Artificial Intelligence

We use AI tools in our business:

  • Claude (by Anthropic): We use Claude to help with customer service, data analysis, and content creation. Your personal information (name, email, order details, or messages) may be included in prompts. We have opted out of allowing our data to be used for AI model training.
  • Pipeboard (by Artell): We use Pipeboard to analyse our advertising performance on Meta and Google. It accesses ad campaign data from our accounts (which may include hashed customer identifiers) and processes it through AI to generate reports and recommendations. Pipeboard does not currently use this data for AI training but reserves the right to do so in future with notice and an opt-out.
  • Klaviyo: Uses machine learning to predict customer behaviour, optimise email timing, and segment audiences based on your purchase and browsing history.
  • Meta and Google: Use machine learning to determine which users see our ads, based on pixel data, uploaded audiences, and their own data about your interests.

For context, Meta and Google separately use data collected through their platforms to develop and improve their AI products. We opt out of AI training where possible.


4. Who Your Information Is Shared With

Your personal information is shared with the following service providers, each of which processes data for the purposes described in this policy.

Service Purpose Data location
Shopify (Canada/USA) Ecommerce platform, payment processing, order management Canada, USA
Klaviyo (USA) Email marketing, customer segmentation, predictive analytics USA
Meta Platforms (USA) Advertising on Facebook and Instagram, conversion tracking USA
Google (USA) Website analytics (GA4), advertising (Google Ads), product listings (Merchant Center) USA
Microsoft Clarity (USA) Website analytics and session recording USA
Anthropic / Claude (USA) AI-assisted customer service, data analysis, content creation USA
Pipeboard (Artell, USA/Brazil) AI-powered advertising analytics and campaign reporting USA
Stamped.io (Canada) Product reviews — your first name and last initial are displayed publicly with your review Canada
BOGOS.io (USA) Promotional offers and bundle logic (processes cart data within Shopify) USA
Outer Signal (USA) Customer analytics, profile enrichment, audience segmentation USA
Adzviser (USA) Marketing analytics reporting USA
Ecommerce Media (Australia) Business consulting — has access to our Meta and Google ad accounts as part of their services Australia
Canva (Australia) Graphic design for marketing materials Australia, USA
MyHost (New Zealand) Business email hosting New Zealand
NPFulfilment (Australia) Order fulfilment — picks, packs, and dispatches your orders; has team members in India with access to customer data Australia, India
NZ Post (New Zealand) Parcel delivery and tracking New Zealand

Your information may also be disclosed where required by law, including to the NZ Police, Privacy Commissioner, Inland Revenue, or a court.

Your personal information is not sold to any third party.


5. International Data Transfers

Most of our service providers are based outside New Zealand, primarily in the United States, Canada, and Australia. Our fulfilment provider (NPFulfilment) also has team members in India, and our business consultants (Ecommerce Media) have service providers in several countries including Brazil, Vietnam, and the Philippines.

Your personal information is transferred to and processed in these countries. Each provider's data handling is governed by their terms of service, which include data processing obligations. Where available, we rely on recognised data protection frameworks such as standard contractual clauses and the EU-US Data Privacy Framework.

We regularly review the privacy practices of our service providers.


6. Marketing

We send marketing emails through Klaviyo and comply with the Unsolicited Electronic Messages Act 2007.

We only send you marketing where you have given consent (by subscribing, opting in at checkout, or otherwise requesting it) or where we have a reasonable basis to believe you would expect to hear from us based on an ongoing customer relationship.

Every marketing email identifies The Hotel Sheet as the sender, includes our contact details, and contains a one-click unsubscribe link. We process unsubscribe requests within 5 working days. Unsubscribing does not affect transactional emails such as order confirmations and shipping notifications.


7. Cookies

Our site uses cookies for three purposes: making the website work (cart, checkout, login), analytics (understanding how visitors use the site), and advertising (measuring ad effectiveness and serving targeted ads).

You can control cookies through your browser settings. You can also manage ad personalisation through Meta's ad settings and Google's ad settings.


8. Data Retention

We keep your information only as long as necessary:

  • Orders and accounts: For the life of your account, plus 7 years after your last order (tax record-keeping under the Tax Administration Act 1994).
  • Marketing data: Until you unsubscribe. We keep your email on a suppression list to prevent re-contact, and remove other profile data within 90 days.
  • Analytics: Session recordings are retained for up to 30 days. Aggregated data may be retained indefinitely.
  • Customer service: 3 years after the last interaction, or longer if related to an unresolved matter.
  • Advertising platforms: Subject to those platforms' own retention policies.

9. Your Rights

Under the Privacy Act 2020:

  • Access: You can request a copy of the personal information we hold about you. We will respond within 20 working days.
  • Correction: You can ask us to correct any inaccurate or incomplete information.
  • Deletion: We will delete your information on request, unless we are legally required to keep it (e.g. tax records).
  • Unsubscribe: You can opt out of marketing at any time via the link in any email, or by contacting us.
  • Complain: You can complain to us, or directly to the Office of the Privacy Commissioner at www.privacy.org.nz.

To exercise any right, email privacy@thehotelsheet.co.nz. We may need to verify your identity.


10. Security and Breaches

We protect your information using Shopify's PCI-DSS compliant payment infrastructure, encrypted connections (HTTPS/TLS), strong passwords and two-factor authentication for staff, and restricted access to customer data.

No system is completely secure. If you become aware of unauthorised access to your account, please contact us immediately.

If we become aware of a privacy breach likely to cause serious harm, we will notify the Privacy Commissioner and affected individuals as required by Part 6 of the Privacy Act 2020.


11. Other

Children: Our products are not directed at children under 18. We do not knowingly collect children's personal information.

Third-party links: Our site links to third-party websites. We are not responsible for their privacy practices.

Changes: We may update this policy from time to time. Material changes will be notified by email or prominent website notice at least 14 days in advance.


12. Contact Us

Vila Mourisca Ltd t/a The Hotel Sheet
PO Box 68-578 Victoria Street West, Auckland 1145, New Zealand
Email: privacy@thehotelsheet.co.nz

Office of the Privacy Commissioner: www.privacy.org.nz | 0800 803 909