My ETA uses personal information to provide customer arrival communication, tracking, account management, messaging and related services. We do not sell personal information and we do not use customer messaging data for third-party advertising.
Who we are and what this policy covers
My ETA is a trading name of OPTIM Limited, New Zealand company number 8376277. In this Privacy Policy, “My ETA”, “we”, “us” and “our” mean OPTIM Limited trading as My ETA.
This Privacy Policy applies to personal information handled through the My ETA mobile application, administration portal, public tracking pages, websites, customer messaging, integrations, support channels and related services.
It may apply to business administrators, drivers, employees and contractors of organisations using My ETA, customers or recipients whose details are supplied for a job, website visitors and people who contact us.
Our role and your organisation’s role
Businesses using My ETA generally decide which customers they contact, what job information they provide, and why customer information is supplied to My ETA. Those organisations remain responsible for their own collection notices, consent processes, customer relationships and legal obligations.
Where privacy law recognises roles such as controller, business, agency, processor or service provider, My ETA will generally act as a processor or service provider for Customer Data when we handle it to provide the Services on an organisation’s instructions. We may also act independently for limited purposes such as account administration, security, fraud prevention, billing, legal compliance, service improvement and our own compliance records.
Information we collect
Depending on how My ETA is used, we may collect or receive:
- Account and organisation information: name, email address, organisation, role, authentication identifiers and account settings.
- Customer and job information: customer name, phone number, email address, collection or service addresses, job numbers, appointment details, status and notes.
- Location and tracking information: driver or device location, timestamps, route-related information, distance and ETA data while tracking or related features are active.
- Device and technical information: device type, operating system, notification tokens, app version, IP address, browser information, diagnostic and security logs.
- Messaging information: phone numbers, message content, inbound replies, delivery status, provider identifiers, opt-out status and message timestamps.
- Integration data: information supplied through connected systems, APIs or supported platforms such as job, booking or dispatch systems.
- Billing information: transaction references, credit balances, billing contact information and payment status. We generally rely on payment providers to process card details rather than storing full payment-card numbers ourselves.
- Support and compliance information: support messages, uploaded files, consent-process descriptions, compliance declarations, evidence files, review status and audit records.
Where information comes from
We may receive personal information:
- directly from you when you create an account, contact us, configure My ETA or use the app;
- from the organisation providing the delivery, move, job or service;
- from a driver’s or worker’s device when tracking or app functionality is active;
- from customers or recipients who reply to messages or use a tracking page;
- from connected integrations and systems authorised by an organisation; and
- automatically through logs, security tools, browser or app functionality and service providers.
When information is supplied to us by someone else
My ETA often receives a customer’s name, phone number, address or job information from the organisation providing that customer’s delivery, move, job or service. This is an indirect collection of personal information.
Where required by law, we take reasonable steps to notify the person — or to ensure they have already been made aware — that My ETA has received their information, why it was received, who may receive it, who holds it, and how they can exercise access or correction rights.
Depending on the circumstances, this may be done through the organisation’s booking or consent flow, its customer agreement, a My ETA tracking page, the first service-related message, or another appropriate notice. Our business customers agree to assist with this process and to provide accurate collection and consent notices where required.
How we use personal information
We may use personal information to:
- create and manage accounts, organisations, roles and permissions;
- provide tracking, ETA, arrival-status and dispatch functionality;
- send and manage service-related SMS, email and push notifications;
- process inbound customer replies and display authorised message history;
- operate integrations, APIs and connected services;
- manage credits, billing, payments and account administration;
- provide support and troubleshoot technical issues;
- detect abuse, spam, fraud, security threats and unauthorised access;
- review messaging-compliance information and maintain audit records;
- maintain, analyse and improve reliability, usability and performance; and
- comply with law, regulators, court orders, lawful requests and our contractual obligations.
Where a particular law requires consent or another specific legal basis for processing, we or the relevant organisation using My ETA are responsible for obtaining that basis as applicable to our respective roles.
Customer messaging and phone numbers
My ETA customer messaging is intended primarily for transactional communications about an active delivery, move, job or service. This can include tracking links, ETA updates, nearly-there messages, arrival notifications, changes or delays, and service-related two-way replies.
We process phone numbers, message content, delivery information, opt-out status and related metadata to deliver the service, route replies, respect opt-outs, support customers, maintain security and meet compliance obligations.
We do not sell phone numbers or customer message content, and we do not use customer message content for targeted advertising or third-party marketing.
Location and tracking data
When a tracked job is active, My ETA may collect precise or approximate device location, timestamps and related movement information to provide live tracking, ETA calculations, arrival notifications and operational views.
Depending on device permissions and configuration, location collection may continue while the app is in the background during an active job. Tracking is intended to stop when the relevant job or tracking session ends.
Organisations using My ETA are responsible for informing their drivers, employees and contractors about workplace or operational tracking and obtaining any permissions required by applicable law or employment arrangements.
Precise geolocation may be treated as sensitive personal information under some laws, including certain United States state privacy laws. My ETA uses precise location only for purposes such as providing the requested tracking, ETA, operational, security and support functionality. We do not sell precise geolocation data or use it for targeted advertising.
Who we share information with
We do not sell personal information. We may disclose or make information available where reasonably necessary to:
- the organisation responsible for the relevant job, delivery, move or service and its authorised users;
- cloud hosting, database, authentication, infrastructure and security providers;
- SMS, telecommunications, email and push-notification providers;
- mapping, routing and geolocation providers;
- payment and billing providers;
- connected systems and integration providers authorised by the organisation;
- professional advisers, insurers, auditors or contractors who need access for legitimate business purposes and are subject to appropriate obligations;
- regulators, courts, law-enforcement agencies or other parties where disclosure is required or authorised by law; or
- a purchaser, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and legal requirements.
International processing and transfers
My ETA is operated from New Zealand and uses service providers and infrastructure that may process personal information outside the individual’s country.
Our principal service-provider locations relevant to the My ETA service currently include New Zealand, Australia and the United States. Some global providers may also process information in other countries according to their infrastructure, support and subcontracting arrangements. You may contact our Privacy Officer if you would like more information about the locations relevant to a particular processing activity.
Where New Zealand Information Privacy Principle 12, Australian Privacy Principle 8, or another applicable cross-border privacy rule applies to a disclosure, we take reasonable steps intended to ensure that the receiving party is subject to appropriate privacy safeguards, contractual protections or another lawful transfer mechanism.
Where a provider acts only on our behalf for storage or processing and the law treats that arrangement differently from a disclosure, we still require appropriate security and confidentiality protections.
How long we keep information
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, to provide the Services, maintain security and business records, resolve disputes, support customer requirements, and meet legal or regulatory obligations.
Retention periods vary by data type and configuration. For example:
- active tracking data may be short-lived, while historical trip information may be retained where an organisation has enabled a history feature;
- message content and delivery metadata may be retained for operational support, customer history, opt-out records and compliance purposes;
- account, billing and transaction records may be retained for accounting, tax, fraud and legal purposes;
- messaging-compliance declarations, evidence and review records may be retained for the life of the relevant customer relationship and for a reasonable period afterwards to support audit, legal and regulatory requirements; and
- security, audit and diagnostic logs may be retained for periods appropriate to investigating incidents and maintaining the integrity of the Services.
When information is no longer reasonably required, we may delete, securely destroy or de-identify it, subject to lawful retention requirements and technical backup cycles.
Security
We use reasonable technical and organisational safeguards appropriate to the nature of the information we handle. Measures may include authentication and role-based access, encryption in transit, provider security controls, restricted administrative access, monitoring, logging, backups, secure secret management and software maintenance.
No internet-connected system is completely secure. You are responsible for protecting your own devices, credentials and user access. Please contact us promptly if you believe your account or information may have been compromised.
Payments
Payments may be processed by third-party payment providers. We may receive payment status, transaction identifiers, customer or billing references and limited payment metadata, but we generally do not store full payment-card numbers in My ETA systems.
Payment providers handle information under their own privacy and security practices as well as any contractual obligations they owe to us.
Cookies, local storage and technical data
Our web applications may use cookies, browser storage or similar technologies that are necessary for authentication, security, session management, preferences and core functionality.
We may also collect technical and usage information to understand reliability and diagnose problems. My ETA does not use customer job or messaging data for cross-context behavioural advertising.
Your privacy rights
Depending on where you live and which privacy laws apply, you may have rights to request access to personal information, ask for correction, request deletion in some circumstances, object to or restrict certain processing, request portability, withdraw consent, or complain about how information has been handled.
Some information held in My ETA belongs operationally to the organisation providing your delivery, move, job or service. If your request concerns information that organisation controls, we may refer you to that organisation or work with it to respond.
We may need to verify your identity before actioning a request and may retain information where required or permitted by law.
New Zealand privacy information
OPTIM Limited is subject to the New Zealand Privacy Act 2020 where that Act applies. New Zealand individuals may request access to and correction of personal information in accordance with the Act.
New Zealand Information Privacy Principle 3A applies to certain indirect collections from 1 May 2026. Where it applies, reasonable steps must be taken to make the individual aware of the collection and specified information about it, unless an exception applies. Section 5 of this policy explains how My ETA approaches indirect collection.
If you have a privacy concern, contact our Privacy Officer first. If you are not satisfied with our response, you may be entitled to complain to the Office of the Privacy Commissioner.
Australian privacy information
Where the Australian Privacy Act 1988 and Australian Privacy Principles apply to My ETA or to a relevant handling activity, we aim to handle personal information consistently with those requirements, including collection transparency, access and correction, security and cross-border disclosure obligations.
To make an Australian privacy complaint, contact our Privacy Officer using the details below and describe the issue and the outcome you are seeking. We will acknowledge and investigate the complaint and aim to provide a substantive response within a reasonable period, generally within 30 days.
If you remain dissatisfied and the Australian Privacy Act applies, you may be able to complain to the Office of the Australian Information Commissioner.
United States state privacy rights
Some United States state privacy laws provide residents with rights such as access, correction, deletion, portability, and the ability to opt out of certain sales, sharing or targeted advertising, but those rights apply only where the relevant law applies to My ETA and to the individual.
My ETA does not sell personal information for money and does not use customer job, tracking or messaging data for targeted advertising. Where a state law treats activities such as cross-context behavioural advertising as “sharing” or “sale”, My ETA does not use customer job, tracking or messaging data for those purposes.
If an applicable state privacy law gives you a right to know, access, correct, delete, obtain a portable copy, limit certain uses of sensitive personal information, opt out of covered sale or sharing, or appeal a denied request, you may exercise that right by contacting our Privacy Officer. We may verify your identity and apply any lawful exceptions.
We will not unlawfully discriminate against an individual for exercising a privacy right.
Children
My ETA is designed for business and operational use and is not directed to children. We do not knowingly create My ETA accounts for children who cannot lawfully consent to the relevant account relationship.
Customer information supplied for a legitimate delivery, move, job or service may incidentally relate to a minor, for example where a parent or guardian is the customer. Organisations using My ETA should minimise the information they supply and ensure any required authority exists.
Privacy and security incidents
If we become aware of a privacy or security incident affecting personal information, we will investigate it and take reasonable steps to contain and remediate the issue.
Where applicable law requires notification to affected individuals, customers, regulators or another authority, we will make or support those notifications as required, taking into account our role in relation to the affected information. This includes, where applicable, New Zealand notification requirements for privacy breaches that have caused or are likely to cause serious harm and Australia’s Notifiable Data Breaches scheme for eligible data breaches.
Questions, requests and complaints
You may contact us to:
- ask what personal information we hold about you;
- request correction of information you believe is inaccurate;
- exercise another applicable privacy right;
- ask how your information is being used; or
- make a privacy complaint.
Please provide enough information for us to understand and locate the relevant information. We may need to verify your identity. We will respond within the period required by applicable law and otherwise aim to respond within 30 days.
Changes to this Privacy Policy
We may update this Privacy Policy as My ETA, our providers or applicable laws change. The current Version and Effective Date are shown at the top of this page.
Where a change materially affects how we handle personal information, we will take reasonable steps to provide additional notice where appropriate.
Privacy Officer and contact details
Privacy Officer
OPTIM Limited trading as My ETA
New Zealand company number 8376277
Email: support@myeta.co
Website: myeta.co
If you are contacting us about a My ETA message sent by another business, please include the phone number that received the message and enough information to identify the relevant organisation or job. Do not send sensitive personal information unless we ask for it.