top of page
cc44b5c8d0fe2b64ebf86f6744ae780e031f08aa_edited.jpg
Login
Sign up

SWISH PRIVACY POLICY

Swish Limited  |  Version 5.0  |  Effective 1st September 2026

Overview

Swish connects to your bank accounts, with your permission, through Akahu, so you can see all of your money in one place. Your transaction data is encrypted on your device with a key only you hold. We store it, but we cannot read it. We use what we can see to run Swish and nothing else. We do not sell your information. You can disconnect an account or delete everything at any time.

1.  WHO WE ARE

Swish Limited (Swish, we, us, our), New Zealand company number 9411815, Level 5, Staircase Financial House, 32-34 Mahuhu Crescent, Auckland CBD 1010. We are the agency responsible for your personal information under the Privacy Act 2020. Contact our Privacy Officer at privacy@swish.co.nz.

This policy explains what we collect, why, who else is involved, how long we keep it, and your rights. It forms part of our Terms of Service.

2.  WHAT WE COLLECT

2.1  From you

Your name, email address and mobile number. Your authentication credentials. Preferences you set, such as budgets, goals, reminder dates and notification settings. Anything you tell us in support requests or feedback.

Biometrics stay on your device. If you use a passkey, the fingerprint or face check happens on your device through your device's own security. That biometric information is never sent to us and we never hold it.

2.2  From your connected accounts, through Akahu

When you sign in and your accounts are refreshed, we receive account details, balances, and transaction history, including the date, amount, description, merchant and categorisation of each transaction. Where the institution provides it, we also receive the name on the account, credit limits, interest rates and loan details.

We ask for up to 12 months of history when you first connect. After that, your accounts are refreshed when you sign in to Swish. We do not fetch your data while you are signed out.

We never see your banking login. You authorise the connection inside Akahu's own secure flow. Your internet banking username, password and access codes are not disclosed to Swish and are not held by us.

2.3  Automatically

Device and technical information, including device model, operating system, app version and a device identifier. Log information, including IP address, access times and errors. Analytics about how Swish is used. Your account and transaction data is excluded from our logs and from our error reporting.

2.4  What we can read, and what we cannot

This is the most important thing to understand about Swish. Your account and transaction data is encrypted on your device with a key that only you hold. We store that encrypted data, but we cannot decrypt it and we cannot read it. Section 6 explains how this works and what it means if you lose your key.

Information we can read includes your name, email address and mobile number, your device and log information, the content of your support requests, and information you enter directly for a feature that needs it, such as a reminder date you ask us to notify you about.

Your account balances, transaction history and the categorisation, budgets and insights built from them are encrypted and are not readable by us.

3.  WHY WE COLLECT IT

3.1  To run Swish

To create and operate your account, authenticate you, connect your accounts and deliver your data to your device. To send you the alerts and reminders you have set up. To tell you when a connection stops working. To answer your questions and fix problems. To detect and prevent unauthorised access, fraud and misuse. To analyse use and improve Swish. To meet our legal obligations and respond to lawful requests.

Categorisation, budgets, insights and summaries are produced on your device, from data only your device can read.

3.2  Cost, and future changes

Swish is currently free to use. We may introduce paid plans or paid features in future. If we do, we will tell you in advance, and no charge will apply to you unless you accept it.

We do not make money from your information. We do not sell your personal information, we do not give your data to anyone for their own marketing, and we do not let advertisers or data brokers access it. If we introduce any new way of using your information, we will tell you first and, where the law requires it, ask for your agreement before we do so.

3.3  Other uses

We will not use your personal information for a purpose other than those set out above unless you authorise it, or the Privacy Act allows it. We may create anonymised and aggregated information that cannot reasonably identify you, and use that without restriction.

4.  WHO ELSE IS INVOLVED IN YOUR INFORMATION

4.1  Our promise

We do not give your information to anyone to use for their own purposes. We do not sell your personal information. We do not give your data to anyone for their own marketing. We do not let advertisers or data brokers access it. The only third party that receives your information for its own use is Akahu, which operates the account connection.

4.2  Providers who hold information for us

We use a small number of providers to run Swish, covering cloud hosting, sign in and authentication, analytics, error reporting, communications and customer support. We also use software development and support contractors, some of whom are located outside New Zealand, to build and maintain Swish.

These providers store or process information on our behalf. They can only use it to provide those services to us, on our instructions, under written confidentiality and security obligations. They cannot use it for their own purposes. Under section 11 of the Privacy Act 2020, information a provider holds on our behalf in this way is treated as held by us, not disclosed to them.

Our hosting provider stores your encrypted account and transaction data. Like us, it cannot decrypt it. Access to production systems by our development and support contractors is restricted to what is needed for support and defect resolution, and is logged.

A current list of the named providers we use, and where information is held, are as follows:

  • Microsoft

  • Akahu

  • Atlassian

  • Zitadel

4.3  Akahu

Akahu Technologies Limited operates the account connection. Akahu handles your authorisation and supplies your account and transaction data to us. Akahu is an independent New Zealand company, not our agent, with its own consumer terms and privacy policy at akahu.nz. You can manage or revoke every app you have connected through Akahu at my.akahu.nz.

4.4  Other situations

We may also disclose personal information to our professional advisers, auditors and insurers where reasonably required, to regulators, courts and law enforcement where required or permitted by law, and as part of a sale or restructure of our business on terms requiring the recipient to protect it to at least the standard in this policy. Where information is encrypted, we can only provide it in encrypted form, because we cannot decrypt it.

5.  INFORMATION HELD OUTSIDE NEW ZEALAND

Some of our providers hold information outside New Zealand. Where a provider holds information on our behalf and may only use it on our instructions, that information is still treated as held by us under the Privacy Act.

Where we disclose personal information to an overseas recipient in a way that is not covered by that rule, we take the steps required by information privacy principle 12, which in practice means binding the recipient by contract to protect the information with safeguards comparable to those in the Privacy Act. Information is currently held in New Zealand only.

6.  HOW YOUR DATA IS PROTECTED

6.1  Your data is encrypted with a key only you hold

Your account and transaction data is encrypted on your device using an encryption key that only you hold. We do not have that key, we cannot obtain it, and we cannot decrypt the data we store for you. Your hosting provider cannot either.

This means that categorisation, budgets, insights and summaries are all produced on your device. It also means that if our systems were ever compromised, your account and transaction data would not be readable.

6.2  If you lose your key, your data cannot be recovered

Please take this seriously. Because only you hold your encryption key, we cannot reset it, recover it, or restore your data without it. If you lose your key, your stored data is permanently unrecoverable. You will need to create a new account and reconnect your accounts to start again. When you sign in on a new device you will be asked for your key.

6.3  The one point where your data passes through our systems

Akahu requires that all communication with its platform happens from our servers rather than from your device. When you sign in and your accounts are refreshed, your data therefore passes through our systems on its way to your device, before it is encrypted.

At that point, your data is not written to our database in readable form, is excluded from our application logs, and is excluded from our error and crash reporting. It is encrypted on your device before it is stored. Because refreshes only happen when you sign in, this does not occur while you are signed out.

We tell you this because we would rather be accurate than overstate what we do. It is the only point at which your account data exists in readable form in our systems.

6.4  Other security measures

We take reasonable steps to protect your personal information from loss, misuse and unauthorised access. Those steps include encryption of all data in transit, encryption of your Akahu access credentials, restricting access to production systems to named personnel on a least privilege basis, requiring multi-factor

authentication for access to account connection features, and having Swish independently security tested.

No system can be completely secure. If a privacy breach occurs that has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as required by Part 6 of the Privacy Act 2020.

7.  HOW LONG WE KEEP IT

We keep personal information only for as long as we reasonably need it for the purposes above, or for as long as the law requires. If you disconnect an account, or revoke our access through Akahu, we stop receiving new data immediately. If you delete your Swish account, we revoke our access to all connected accounts and delete your information immediately, other than records we are required to keep by law, information needed to resolve an open complaint or dispute, and copies in secure backups until those backups expire in the ordinary cycle. Encrypted data in backups remains unreadable to us.

8.  YOUR CONTROLS

  • Swish shows you every account you have connected, at any time.

  • You can disconnect any account, or all of them, from within Swish, or revoke our access directly with Akahu at my.akahu.nz.

  • You can delete your Swish account from within the app at any time.

  • You can turn off marketing messages at any time. We will still send messages about your account and service issues.

9.  ACCESS AND CORRECTION

  • You have the right to ask for access to the personal information we hold about you and to ask us to correct it. Contact privacy@swish.co.nz. We will respond within 20 working days and may need to verify your identity first. If we decline a request we will tell you why and explain your right to complain to the Office of the Privacy Commissioner.

  • A limit you should know about. We cannot decrypt your account and transaction data, so we cannot provide it to you in readable form. Your own device can. If you ask us for that information we can provide it only in encrypted form. Everything we can read, we will provide.

  • If information is wrong because it came from your financial institution, we can only correct it at our end. You will also need to raise it with that institution, because their record is the source.

10.  COOKIES

Our website uses cookies and similar technologies for essential functionality, security and analytics, and our app uses device identifiers and analytics tools for the same purposes. You can control cookies through your browser settings, though some parts of the site may not work properly if you disable them.

11.  CHILDREN

Swish is not intended for anyone under 18 and we do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it.

12.  CHANGES

We may update this policy. If a change materially affects how we use your information, we will give you at least 14 days notice in the app or by email before it takes effect, and describe what has changed. The current version is always available in the app and at swish.co.nz/privacy-policy

13.  COMPLAINTS

If you are concerned about how we have handled your personal information, contact our Privacy Officer at privacy@swish.co.nz. We will acknowledge within 2 working days and aim to resolve within 20 working days. If you are not satisfied, you can complain to the Office of the Privacy Commissioner: privacy.org.nz, 0800 803 909, PO Box 10094, Wellington 6143.

bottom of page