Legal · Last updated 8 August 2026
Privacy policy
Sneaker Local is a New Zealand marketplace where strangers buy and sell sneakers. That only works if you can trust us with the few things we have to know about you. This page says exactly what those are, who else ever sees them, and how to get them back or get rid of them. It is written in plain language on purpose.
Who we are
Sneaker Local operates sneakerlocal.com and the Sneaker Local iPhone app, from New Zealand. We are the agency responsible for the personal information described here under the Privacy Act 2020. You can reach us at support@sneakerlocal.com.
What we collect, and why
We collect the smallest set of things that lets a sale actually complete. Nothing here is collected for advertising, because we do no advertising.
- Your account. An email address and a password. The password is never stored — only a one-way hash of it, which cannot be turned back into your password. We also generate a handle for you, like SwiftKiwi428, which is the name other people see.
- Listings you post. Photos, the condition and size you enter, your description, and your asking price. Photos are re-encoded on our server the moment they are uploaded, which removes the metadata a phone camera embeds — including the GPS coordinates of the room the photo was taken in. We then check the stored bytes to confirm it is gone rather than trusting that it worked.
- Delivery details, when you buy. The address the shoes are going to. It is used to price and print the courier label, and it becomes visible to the seller because it is where they are sending a parcel.
- Payout details, when you sell. Our payment processor collects and verifies your identity documents and bank details directly. We do not see them. What comes back to us is whether you passed, whether you can be paid, your payout schedule, and the pickup address the courier label is raised on.
- Messages. What you and the other person write to each other about a listing or an order. We store them so the conversation persists, and we read them when a dispute is raised and somebody has to work out what happened.
- Order and payment records. What was bought, for how much, when, and the reference our payment processor gave the transaction.
- Operational logs. Ordinary server records — requests, errors — kept so we can fix things that break. They are not used to build a profile of you.
Card details never touch us
When you pay, the card fields you type into are served directly by our payment processor inside our checkout page. Your card number does not pass through our servers and is not in our database — there is no column anywhere in this product that holds a card number, and there never has been. We hold the processor's reference for the payment and the amount, and nothing else about the card.
Your money is held until you say the shoes are right
Because payment is held rather than passed straight on, we keep the record of a trade for as long as it could still be argued about — a refund, a chargeback, or a dispute. That is the main reason order records outlive an account. See Keeping and deleting, below.
Strangers stay strangers
Publicly — on a listing, in the browse feed, on an offer — you are your handle. Your legal name is not shown, and neither is a profile photo: the product has no avatars at all, deliberately.
Your real name becomes visible to one specific person, the buyer or seller on the other side, only once a trade between you two has actually been paid for. At that point they are addressing a parcel to you or receiving one from you, so the pretence would be worse than useless. That reveal is permanent between those two people and applies to your earlier messages with them as well. It never extends to anybody else on the platform.
We can see your real name too. It is used when we email you, and when somebody at Sneaker Local has to resolve a dispute between two people.
What we do not do
- We do not sell, rent or trade your personal information. Not to anyone, not for anything.
- We run no advertising and carry no advertising trackers or pixels.
- We use no third-party analytics — no page-view tracker, no session recorder, no tag manager. There is none of that software in this product.
- We set one cookie, and only after you sign in: the one that keeps you signed in. Visiting the site signed out sets no cookies at all.
- We do not track your location. See below.
Location
The website does not ask for, receive or store your location. There is no location permission prompt and no location data in our database.
The iPhone app will ask. When it does, it asks so it can show you pairs near you, and what it keeps is coarse — a suburb or region, like “Grey Lynn, Auckland” — never a street address and never a continuous trail of where you have been. You can refuse the prompt and the app still works; you just browse the whole country instead of your part of it. We will update this page when that ships.
Photos and metadata, precisely
Photos you attach to a listing are stripped of embedded metadata, as described above. That is a deliberate feature, not a side effect, and it is verified on every upload.
Photos you upload as dispute evidence, or of a shipping label when you arrange your own courier, are not stripped. For a dispute the timestamp and the camera details can be the whole point of the photo. Keep that in mind when you choose which photo to send.
If you use the optional draft-from-photos helper when writing a listing, the links to those listing photos are sent to an AI provider so it can suggest a title, condition and description for you to edit. Those photos have already had their metadata removed. The helper is a shortcut on top of the manual form; the form works perfectly well without it.
Who else sees your information
Only the people and services that have to, and only the part they need:
- The other person in a trade — after a trade is paid for, as described above.
- Our payment processor— to take the payment, hold it, pay the seller, and verify a seller's identity. They are the ones who see card and bank details.
- Our courier — the delivery and pickup addresses, to price the shipment and print the label.
- Our email provider — your email address, to send you the notifications a trade generates. They tell us whether an email was delivered or bounced, so we know when you are not hearing from us.
- Our hosting, storage and database providers — they run the servers your data sits on.
- An AI provider — only if you use the optional listing-draft helper, and only the listing photos, as described above.
- Anyone the law requires — a court order, the police, or a regulator with the authority to ask.
Several of these providers are based overseas, including in the United States, so your information is stored and processed outside New Zealand. We choose providers who are contractually required to protect it to a comparable standard. We are a small operation and we are happy to tell you exactly who they are — just ask.
Notifications
Trade notifications go to your email address, because that is the channel that always arrives. If you turn on browser or app push notifications, we store the token your device gives us so we can send to it. Turning them off removes it.
Keeping and deleting
Your account, listings and messages are kept while your account exists. Records of completed trades and payments are kept for at least seven years after the trade, because New Zealand tax and business record rules require it and because a chargeback or dispute can arrive long after a sale looks finished.
You can ask us to delete your account by emailing support@sneakerlocal.com. We will remove your listings and your account, and anonymise what we are required to keep. We cannot action a deletion while you have an open trade or a live dispute — there is somebody on the other side of it — so those have to finish first.
One thing survives deletion by design: if an account has been banned for fraud or abuse, we keep a one-way fingerprint of the verified identity or email it was banned on. It cannot be turned back into your details. It exists so that a banned person cannot simply delete the account and sign up again, which is a promise we make to everybody else on the platform.
Security
Everything is served over HTTPS. Passwords are stored only as one-way hashes. Your session lives in a cookie your browser will not hand to another site, and on the app it is held in the iPhone's Keychain. Access to production data is limited to the people who operate the service. No system is perfect, and we would rather tell you that than claim otherwise.
Your rights
Under the Privacy Act 2020 you can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Email support@sneakerlocal.com and we will respond within 20 working days.
If you think we have got it wrong and we have not put it right, you can complain to the Office of the Privacy Commissioner at privacy.org.nz.
Children
Sneaker Local is not intended for children. You need to be able to enter a binding sale and hold a payment card to use it. If we learn that an account belongs to a child, we will close it and delete what we hold.
Changes to this policy
When we change how any of this works, we change this page and move the date at the top. If a change materially affects what we do with information we already hold, we will email you about it rather than rely on you noticing.