GoCarma by Tower Privacy Policy

27 November 2020

At Tower we are committed to protecting your privacy and think that is important that we are transparent about how we collect, use, and share information about you. In this Privacy Policy (“this Policy, Privacy Policy”) you can find the following information:

  • What information we ask you to provide directly to us and why
  • What information does the Tower GoCarma application collect and access when it is used and why
  • What information might be collected from other sources
  • To which third parties may we transfer your data
  • How we store and secure information we collect
  • How to access and control your information
  • Other important privacy information

By using GoCarma you agree that the information you submit, or which is collected through GoCarma is collected, processed, used and transferred in the manner identified in this Privacy Policy. If you do not agree with this policy, do not access or use the GoCarma mobile application ("GoCarma" or "the app").

Scope and Application

Tower Limited, ("Tower", "we", "us") collects and holds information about you (the user or users of the app) when you sign up for and use the app. This includes any updates, new versions or new releases and related data feeds and services, and if you purchase insurance or have any communications with Tower for these purposes. This Privacy Policy sets out what and how information is collected, why it is collected, to whom it may be transferred and how you may gain access to/request correction of such information or change your choice with regards to receiving promotional material. It is entirely voluntary for you to provide such information, but there is certain information you must provide:

a) to access GoCarma in the first place; and

b) to use all functionalities of the GoCarma app

What information do we need from you in order for you to use the app?

You will note that we collect your first name and surname, and your e-mail address when you first register for GoCarma. This information will be used to generate a My Tower account, which is required in order for you to use the app. We will also ask you to complete certain information in the Profile section of the app. The information we ask you to provide and why is as follows:

Your e-mail address - When you first download and open GoCarma, we ask you to provide your e-mail address. This email address will serve as your primary email for GoCarma and for My Tower. Without your e-mail address, you will be unable to create an account to access the app. We also use your e-mail address to communicate with you on queries you may have, or to provide you with information in relation to GoCarma. Further, but only if you have chosen to "opt in" to receiving promotional material, we may use this to send you marketing information or promotional material.

Your name – We collect both your first name and your surname for use within the app and for your My Tower account. Within GoCarma, your first name will be your display name. This will be displayed within GoCarma with your driving score so other users of GoCarma will be able to see this. You need to provide this otherwise you cannot use the GoCarma app. If you choose to enter into any competition, we also ask that you provide your surname/family name as a condition of doing this, for identification purposes (along with your first name).

Car make/car model/car year/vehicle registration number – We collect this information to ensure GoCarma works accurately for your purposes (the make, model and year of the car are important for that), but also for eligibility and identification purposes. You are only eligible to use GoCarma if you have a registered vehicle that you are appropriately licensed to operate. This information is a necessary condition of you accessing the functionality of GoCarma.

What additional information can you provide to us to improve the experience and functionality of the app?

Address/City/Phone number – You may use GoCarma without filling in this information. However, we do give you the option to enter this information. The purpose of asking for this information is to provide us with alternative means of communicating with you about GoCarma if you have any queries (for example, if we cannot get hold of you by your e-mail address). We may also use this to target specific geographical locations for offers or promotions

Birthday –You may use GoCarma without filling in this information. However, we do give you the option to enter this information. The purpose of asking for this information is that it provides us with a check on your eligibility to use GoCarma. It is also another check on your identification. Further (unless you have chosen to "opt out" of receiving promotional material), we may use this to send you special promotions in relation our insurance products.

Expiry date of your current car insurance – This information is not mandatory for you to provide in order to use GoCarma. This information may be used for promotional purposes, such as providing you with a discount based on your GoCarma score, at the time your insurance comes up for renewal, if you fill this in.

What information does GoCarma collect and access when it is used and why?

When you sign up for GoCarma, you will note that we indicate GoCarma requires access to certain information. This information, the reasons access to it is required and1 the time at which it is accessed are set out below:

Location Information – GoCarma functions by collecting precise location data about your trip when you drive. This is necessary to enable GoCarma to detect your acceleration, cornering, speed and other measurements which are factors for determining safe (or unsafe) driving. It is therefore a requirement that GoCarma is granted this permission within your mobile operating system for the main purpose of assessing your record as a safe driver.

Motion Detection – To record the safety measurements of your driving (accelerating, cornering, speed, braking) GoCarma needs to access data from your phone’s GPS, gyroscope and accelerometer sensors. It is therefore a requirement that GoCarma is granted this permission within your mobile operating system for the main purpose of assessing your record as a safe driver.

Network/WiFi states – GoCarma collects your location information in real time whilst you are online. If the connection is interrupted for whatever reason, the information will be stored locally until a connection is available. It is therefore a requirement that GoCarma is granted this permission within your mobile operating system for the main purpose of assessing your record as a safe driver.

Call and SMS data ‐ As a safety feature, GoCarma has the functionality to turn on automatic call and SMS replies for incoming calls and SMS’s received whilst your device is being use to record a driving trip via GoCarma. This enables you to drive without interruption and improve your safety. The use of this function is optional. However, if you decide to use this function, it is a requirement that GoCarma is granted the necessary permissions within your mobile operating system to access the SMS and call functions. We will only utilise these permissions for the stated purposes.

Important information about platform permissions

Most mobile platforms have defined certain types of device data that apps cannot access without your permission and platforms provide different permission systems for gaining your consent. The iOS platform alerts you the first time GoCarma wants access to a particular function (usually the first time you use that function) and asks you to give permission for that function to be used at that point. Android devices will notify you of all the permissions GoCarma may need for all functions when you first register for the app and your use of the app constitutes your consent. The above explanations, we hope, provide you the full details of the functionalities which GoCarma needs access to, why and when it will use them.

What information might be collected from other sources

GoCarma also provides you the functionality to share your score and other information on your social media sites. Your use of such features enables the sharing of information with your friends or the public, depending on the settings you set with your social media service. You should check the privacy policies of your social media sites for further information relating to the collection, use and storage of your personal information on those sites.

GoCarma makes use of social media network plugins ("Plugins"). When these Plugins are used to share your score and other information on your social media sites, information may be directly transferred from your device to the operator of the social network. Please note that GoCarma has no influence on the data gathered by the Plugin. If you are logged into a social network, your use of our Service can be referenced to your social network account. If you interact with the Plugins, for example by clicking “Like”, “Follow” or “Share”, or entering a comment, the information may automatically show in your social network profile. Even if you are not logged into your social network account. It may also be possible that the Plugins transmit your IP address to the social network operators. Please consider this when using our Services.

For information about the social network operators of the Plugins used in our GoCarma please see below:

Facebook Data controller: Facebook Ireland Limited, Hanover Reach, 5-7 Hanover Quay, 2 Dublin, Ireland ("Facebook"). For further information you may visit Facebook’s privacy policy website at https://www.facebook.com/about/privacy/.

Google+ Data controller: Google Inc., Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). For further information you may visit Google’s privacy policy website at http://www.google.co.uk/intl/en/policies/terms/regional.html.

To which third parties may we transfer your data?

We share information with third parties that help us operate, provide, improve, integrate, customise, support and market our GoCarma.

Information collected through GoCarma is collected on cloud servers run by a third party cloud hosting provider. The information is also downloaded to Tower, which utilises shared service hubs run by Tower affiliates or third party cloud hosting companies for data storage and management. On-going application support for GoCarma is provided by a third party software service provider, Amodo d.o.o with whom Tower has a contract for service. In providing such support, Amodo d.o.o requires access to the data collected through GoCarma. If the data is subsequently transferred outside of the cloud server, it will be done so in an irreversibly anonymised form.

For the above third parties to have the data access required, data collected through GoCarma may be transferred to places outside of New Zealand (where the cloud data centres and Tower data centres are based and where the service providers are based). Where such a transfer is performed, it will be done in compliance with the requirements of the applicable Privacy laws.

In cases where there is a need to transfer the personal information to countries outside of New Zealand, Tower will put procedures in place to ensure that privacy protections are the equivalent or better than those required under New Zealand laws.

How we store and secure information we collect

We use data hosting service providers in Australia to host the information we collect, and we use technical measures to secure your data.

Tower has incorporated security procedures and practices that we consider are consistent with New Zealand industry practice for the protection of our customers using the app. We review our security procedures from time to time and update these when relevant. Where we obtain your personal information and/or username and password, we have ensured that information is protected. All data sent from your phone to GoCarma is protected by using a secure encryption protocol. All data stored within the GoCarma solution is encrypted in line with industry cryptographic standards. The username, password and personal data are encrypted when transiting over the internet which prevents tampering with these details.

How long do we keep information

How long we keep information we collect about you depends on the type of information. After such time, we will either delete or anonymise your information or, if this is not possible (for example, because the information has been stored in backup archives), then we will securely store your information and isolate it from any further use until deletion is possible.

Event Outcome
If you request deletion while your data is live It will be deleted from all systems including data lake if it remains live
If you request deletion after anonymisation The anonymised data will be retained indefinitely

What is data anonymisation?

Anonymisation is the process of removing all information that may serve as an identifier of the individual it belongs to.

How to access and control your information

Excess Discount Offer

GoCarma enables you to see the type of excess discount you may be eligible for to obtain based on your driving performance if you meet the Eligibility Criteria.

Promotional Communications

Subject to prior consent from you, we may use your contact information to send you marketing information or promotions. The ways in which we would contact you may include:

  • Email
  • Post
  • Push Notifications via your smart phone (if your device has granted the relevant permissions to GoCarma)
  • Text message
You may opt out of receiving such promotional messages from us at any time by following the instructions on those messages, or alternatively, by contacting us at gocarma@tower.co.nz.

Upon receipt of any opt-out request from you, Tower will, at no cost to you, act on your request and ensure that your personal data will not be used for those purposes and you remain able to use the app.

Your right of access and correction

In respect of any personal data collected from you and held by us through GoCarma, you have the following powers:

  1. To check whether Tower holds data relating to you and to access such data if you wish to; 
  2. To request Tower to correct any data relating to you which is inaccurate;
  3. To object to our use of your information (including for marketing purposes);

If you have any questions or concerns in relation to this privacy policy or if you would like to request access and / or correction of personal data, you may write to the Tower Privacy Officer at privacy@tower.co.nz. The Tower Privacy Officer will, upon satisfying itself of the authenticity and validity of the access request, make every endeavour to comply with and respond to the request within the period set by the New Zealand Privacy Act.  In accordance with the terms, Tower has the right to charge a reasonable amount for the processing of any data access request.

Your request and choices may be limited in certain cases: for example, if fulfilling your request would reveal information about another person, or if you ask to delete information which we or our administrator are permitted by law or have compelling legitimate interests to keep. Where you have asked us to share data with third parties, for example, by installing third-party apps like Facebook, you will need to contact those third-party service providers directly to have your information deleted or otherwise restricted. If you have unresolved concerns, you have the right to complain to the Privacy Commissioner. To do so, please refer to their website www.privacy.org.nz.

Changes to our Privacy Policy

We may change this Privacy Policy from time to time. We will post any Privacy Policy changes on the Internet or GoCarma page and, if the changes are significant, we will provide a more prominent notice by adding a notice on the GoCarma homepages, login screens, or by sending you an email notification. We encourage you to review our Privacy Policy whenever you use the GoCarma to stay informed about our information practices and the ways you can help protect your privacy.

This Privacy Policy becomes effective on 30 November 2020.