Privacy policy
Last updated: 4 August 2026
Who we are
Canari is an insolvency early-warning service for New Zealand businesses, operated by Verion Ventures Limited (NZBN 9429053875129). In this policy “we” and “Canari” mean that operator, which is the agency responsible for your personal information under the Privacy Act 2020 (NZ).
You can reach us about anything in this policy at canari@verionventures.com, or by post at 30A Hamilton Road, Herne Bay, Auckland 1011, New Zealand.
What we collect
We collect only what the service needs to do its job.
Your account. Your email address and the name of your organisation, so you can sign in and so we know which ledger belongs to you. We use passwordless sign-in, so we never hold a password for you.
Data from Xero. When you connect Xero, you grant us read-only access to your contacts. We never write to your ledger. From each customer contact we store their name, their email address if present, and the total amount they owe you (outstanding and overdue). We do not read your invoices, bank accounts, payroll or transactions.
Public register data. We look your customers up against two public sources — the New Zealand Business Number register (operated by MBIE) and the New Zealand Gazette’s insolvency notices — and store what we find, including company details and any insolvency events. This information is already public, and we show it back to you.
Director names, and the single thing we use them for. We store the names of a monitored company’s directors, taken from the public register. We use them to work out which company is which: where two companies share a name, we show each one’s registered address and directors so you can tell which is your customer, and we note when a monitored company’s directors change. That is the whole purpose. We do not use a director’s name to assess that person, we do not keep a profile of any individual, and we do not draw conclusions about anyone from their appointments or resignations.
We monitor companies, not people. Canari only takes on registered companies and other bodies corporate. Sole traders, partnerships and unincorporated trusts are not monitored, so if one of your customers is a sole trader we will tell you they are out of scope rather than watch them.
Emails we send you. A record of each one: the address it went to, its subject, when it was sent, and whether the link in it was clicked. Three kinds reach you — alerts about your customers, the sign-in link you ask for each time you sign in, and an invitation if a colleague adds you. You can turn alert emails off at any time — there is a link in every one, and a switch in Settings. It applies to you alone, not to your colleagues. The other two carry no off switch: one is you signing in, and the other happens once.
How you use Canari. Which screens you open and which decisions you make in the app — confirming a customer, marking an alert dealt with — with the date and your account. We use it to work out which parts of Canari earn their place, and nothing else. It stays in our own database: we do not use Google Analytics or any other analytics company, and we do not record your screen.
Anything you tell us. When you send feedback, we store what you wrote and the address of the page you were on — not what was on it.
How we use it
We use your data to match the customers in your Xero ledger against public insolvency records, to show what each of them owes you, and to email you when something is published about one of them. That is the entire purpose.
We do not sell your data. We do not share it with other Canari customers. We do not use your ledger data to train machine-learning models, and we do not use it for advertising.
How we protect it
Your Xero access and refresh tokens are encrypted at rest using AES-256-GCM before they are written to our database. Every request between you and Canari, and between Canari and Xero, travels over TLS.
Our database enforces row-level security, meaning one organisation’s records are inaccessible to another at the database level rather than only in application code. Access to production systems is limited to the operator named above.
No system is perfectly secure. If we ever suffer a privacy breach that poses a risk of serious harm, we will notify you and the Office of the Privacy Commissioner as the Privacy Act 2020 requires, and — where Xero data is involved — we will notify Xero immediately at api@xero.com.
More detail on security
Our security overview sets out the encryption, access and monitoring arrangements behind this section, and how to report a security problem.
Who else touches your data
We rely on a small number of service providers, each of which may process your data on our behalf:
- Xero — the source of your ledger data, at your direction.
- Supabase — database and authentication, hosted in Sydney, Australia.
- Vercel — application hosting, served from Sydney, Australia.
- Resend — delivery of every email we send you: alerts, sign-in links, and invitations.
- MBIE and the New Zealand Gazette— public register and insolvency-notice lookups. To find the right company we send MBIE a company number, or your customer’s name as it appears in your contact list. We never send either of them your balances, your invoices, or anything identifying you. The Gazette we simply read; it is sent nothing.
Because Supabase and Vercel host in Australia, your data is stored outside New Zealand. Australia is subject to comparable privacy safeguards, and we rely on that in line with information privacy principle 12.
How long we keep it
We keep your data for as long as your account is active. If you disconnect Xero, we delete the stored tokens for that connection. If you close your account, we delete your organisation’s ledger data, contacts and alert history within 30 days, except where we are required to retain records by law.
Archiving or deleting a customer in Xero does not on its own remove them from Canari — a sync adds and updates, but does not remove — so we keep monitoring that company until you tell us. Email us and we will take it off your list.
Director names are held only while a company is being monitored by someone. Once no customer is monitoring a company — because they told us it is not their customer, or closed their account — we delete that company’s director names on the next daily run.
Your rights
Under the Privacy Act 2020 you may ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Write to us at canari@verionventures.com and we will respond within 20 working days.
You can disconnect Xero at any time from Settings in Canari, which revokes Canari’s access at Xero in the same step. You can also revoke it from within Xero itself, under Settings → Connected apps. Syncing stops immediately either way, and you can ask us to delete what we already hold using the address above.
If you are a director of a company we monitor. These rights are not limited to our customers. If your name appears on the New Zealand companies register as a director and we hold it, you may ask us what we hold about you, ask us to correct it, and ask why we hold it — using the same address. We will answer within 20 working days. If a register entry about you is wrong, the register itself is the place to correct it, and we will update our copy.
If you are not satisfied with how we have handled your information, you may complain to the Office of the Privacy Commissioner at privacy.org.nz.
Changes to this policy
If we change this policy materially, we will update the date at the top of this page and email account holders before the change takes effect.