Privacy Policy
This Privacy Policy explains how Cradle Limited ("Cradle", "we", "us", "our") collects, uses, discloses and protects personal information. Personal information is information about an identifiable individual (a natural person), and includes personal data, personally identifiable information and equivalent information under applicable privacy and data protection laws.
This Privacy Policy applies to:
- visitors to our websites;
- customers who contract with us; and
- individuals whose personal information is processed through our services.
This Privacy Policy does not limit or exclude any rights you have under applicable privacy laws. It does not provide exhaustive detail of every aspect of our collection and use of personal information, and we are happy to provide any additional information or explanation you need. Requests for further information should be sent to privacy@cradle.io.
1. Compliance with privacy laws
We comply with applicable privacy and data protection laws, including:
- the New Zealand Privacy Act 2020;
- the Australian Privacy Act 1988;
- the EU General Data Protection Regulation (GDPR); and
- the UK GDPR.
2. Controller and processor roles
2.1 When Cradle acts as a controller
Cradle acts as a data controller where we collect and process personal information for our own purposes, including:
- operating our websites;
- managing customer relationships;
- billing and payments;
- marketing and communications; and
- improving and securing our services.
This Privacy Policy applies to that processing.
2.2 When Cradle acts as a processor
Where our customers upload or otherwise provide personal information to the Cradle service for use as part of their business communications ("Customer Data"), our customers act as the data controller, and Cradle acts as a data processor (or service provider).
That processing is governed by:
- the Cradle Terms of Use; and
- the Data Processing Agreement (DPA), which forms part of the contract between Cradle and the customer.
We require our customers to obtain the consents needed from individuals to provide Customer Data to us and to permit us to process it as set out in our agreements with them. We only process Customer Data as authorised by our customers.
Unless required otherwise under applicable law, if we receive a request or enquiry relating to Customer Data that we hold solely for the purpose of providing our service, we will forward the request to the relevant customer. If you have questions about Customer Data processed on behalf of a customer, you should contact that customer directly.
3. Personal information we collect
3.1 Information collected directly from you
We collect the following information directly from you:
- when you sign up for or log in to an account, we collect your name, email address, phone number, work address, IP address, location, business name, business registration details and any other information we require or ask for to set up your account (some of this may come from third-party authentication services, as described in Section 3.4);
- when you fill in a contact or enquiry form on our website, call us, meet us in person or otherwise contact us, we collect your name, email address, phone number and any other information you choose to provide;
- when you sign up to our newsletter or other electronic alerts, we collect your name, email address and any other information you provide when you subscribe;
- when you respond to our feedback surveys, we collect your name, email address and your feedback response;
- when you refer another person to Cradle, we collect your name and email address, and the other person's name, email address and phone number, together with any other information you choose to include in the referral;
- when you purchase products or services from us, we collect your name, email address, phone number, payment information, business name, business registration details and any other information you submit for billing, regulatory compliance and service provision purposes; and
- when you purchase products that we physically deliver, we collect your name, address, phone number and delivery instructions.
We do not knowingly process sensitive categories of personal information.
Some of the information we collect directly from you is mandatory and some is optional; we will let you know which applies at the time we collect it. If you choose not to provide certain information, our products and services may not perform as well as they should, or we may not be able to provide some parts of them to you.
Payment card information is processed by third-party payment providers. We do not have access to, or store, full card details.
3.2 Information collected automatically on our websites
When you access and use our websites or related services, we may automatically collect information about your device and usage, including your IP address, operating system, browser type, time spent on pages, pages visited and links clicked.
Some of this information is collected through third-party tools and cookies, web beacons and similar technologies. See the Cookie Policy below for detail, including how to disable these technologies.
3.3 Information collected automatically in our applications
When you use or log in to our applications on the web (including admin.cradle.io) or our client applications on Windows, Linux, macOS, iOS or Android, we may collect information including: network information (the public IP address used to connect to our service, relevant local networking information and your connection type), browser information (type, version, time zone and language) and device information (audio configuration, operating system and version).
3.4 Information from third parties
Where possible, we collect personal information from you directly. Sometimes we also collect:
- personal information that is publicly available (for example through LinkedIn profiles, public directories or company registration databases);
- personal information from Google, when you sign up for or log in to Cradle using Google. With your permission, the information collected from Google is limited to: the list of users on your Google Workspace account (for Workspace administrators, to make adding your colleagues easier); your profile, consisting of your first name, last name, profile picture, email address and a unique identifier on the Google platform; and your contacts, so that you can dial your contacts from a Cradle calling application without entering their numbers. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements;
- personal information from Microsoft, when you sign up for or log in to Cradle using Microsoft. With your permission, the information collected from Microsoft is limited to: the list of users on your Microsoft Entra ID account (if applicable); and your profile, consisting of your first name, last name, profile picture, email address and a unique identifier on the Microsoft platform;
- personal information from other third parties where you have authorised this, including practice management and CRM systems you connect to Cradle; and
- personal information included in Customer Data.
We may combine personal information about you received from third parties with information we collect from you directly and with device and usage data collected automatically.
4. How we use personal information
We may use personal information to:
- verify your identity, including using your Google or Microsoft login to verify your email address;
- provide and operate our websites, products and services;
- make it easier to add your colleagues to your Cradle account (colleague lists from Google or Microsoft are presented to you client-side; a colleague's name and email address are only sent to Cradle once you add them);
- market our products and services to you, including contacting you electronically;
- improve, secure and develop our websites, products and services;
- run promotions, such as referral programmes and surveys;
- undertake credit checks (where necessary);
- bill you and collect money that you owe us, including authorising and processing payment transactions;
- respond to communications from you, including enquiries and complaints;
- conduct research and statistical analysis on an anonymised and aggregated basis;
- tailor content or advertisements to you;
- protect and enforce our legal rights and interests, including defending any claim;
- respond to lawful requests by public authorities, including to comply with law enforcement requirements; and
- for any other purpose authorised by you or applicable law.
We conduct automated decision-making to prevent the fraudulent use of communications systems, including uses of our service that contravene spam protection laws.
We may transfer your information in the case of a sale, merger, consolidation, liquidation, reorganisation or acquisition.
You can stop receiving our marketing emails by following the unsubscribe instructions in those emails or by contacting us at help@cradle.io.
5. Emergency calling notice
Cradle provides a cloud-based VoIP service. It is not a replacement for a traditional fixed-line or mobile telephone service.
Emergency calling availability varies by country, configuration and third-party carrier capability. Emergency calls made using VoIP services may not connect, may be delayed, or may not provide accurate location information.
We strongly recommend that users rely on a mobile phone or alternative telephone service for emergency calls.
Further information is set out in our Terms of Use.
6. Disclosing personal information
We may disclose personal information to:
- another company within our group, including subsidiaries formed in the future;
- service providers and subprocessors who support our websites, products and services, including any person that hosts or maintains any underlying IT system or data centre we use, or that we use to process payments;
- a credit reference agency for the purpose of credit checking you (where necessary);
- third parties, for anonymised statistical information only;
- professional advisers, such as accountants, lawyers and auditors;
- a person who can require us to supply personal information, such as a regulatory authority or law enforcement agency;
- any other person authorised by you;
- another company in the case of a sale, merger, consolidation, liquidation, reorganisation or acquisition; and
- any other person authorised by applicable law.
We require service providers to protect personal information appropriately. We may also share information about your use of our websites with our advertising and analytics partners through cookies, web beacons and similar technologies, as set out in the Cookie Policy below.
7. International data transfers
The businesses that support our websites, products and services may be located outside New Zealand (where we are incorporated) and outside the country where you are located. This means personal information we collect may be transferred to, and stored in, a country other than your own.
If you are located in the European Union, your personal information may be transferred outside the European Economic Area (EEA). Under the GDPR, transfers outside the EEA may take place where the European Commission has decided that the destination country ensures an adequate level of protection, or, in the absence of an adequacy decision, where other appropriate safeguards are in place.
If you are located in the United Kingdom, your personal information may be transferred outside the UK on the equivalent basis under the UK GDPR.
Where we transfer personal information outside the EEA or the UK, it will only be transferred to countries identified as providing adequate protection, or to a third party where approved transfer mechanisms are in place to protect the information (for example, standard contractual clauses).
Some of the personal information we collect is processed in New Zealand. New Zealand is recognised by the European Commission as providing an adequate level of data protection, and we rely on this decision when transferring personal information to New Zealand.
For further information, contact privacy@cradle.io.
8. Data retention
We retain personal information only for as long as necessary to:
- provide our services;
- meet contractual obligations;
- comply with legal requirements; or
- resolve disputes.
Customer Data processed under the DPA is retained and deleted in accordance with the Terms of Use and the DPA.
9. Security
As required by applicable law, we take steps to keep personal information safe from loss, unauthorised activity and other misuse. We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks inherent in processing personal information.
No system is completely secure. You play an important role in keeping your personal information secure by maintaining the confidentiality of the passwords and accounts you use with our products and services. We recommend using multi-factor authentication on all authentication services you use to access Cradle. Please notify us immediately if there is any unauthorised use of your account or any other breach of security.
If you follow a link on our website to another website, the owner of that website will have its own privacy policy. We suggest you review it before providing personal information.
10. Children
We do not intend to collect personal information from or about children aged under 16. If you have reason to believe that we have collected personal information from or about a child under 16, please contact us at privacy@cradle.io.
11. Cookies and tracking
We use cookies and similar technologies to operate our websites, analyse usage, improve performance and support marketing activities.
Details of the cookies we use and how to manage them are set out in our Cookie Policy below, which forms part of this Privacy Policy.
12. Accessing and correcting your personal information
Subject to certain grounds for refusal under applicable law, you have the right to access the personal information we hold about you and to request a correction. Before you exercise these rights, we will need evidence to confirm that you are the individual to whom the information relates.
Where you request a correction, if we think the correction is reasonable and we are reasonably able to make it, we will do so. Otherwise, we will take reasonable steps to note the requested correction against the relevant information.
To exercise either right, email privacy@cradle.io with evidence of who you are and the details of your request. Subject to applicable law, we may charge our reasonable costs of providing copies of your personal information or correcting it.
13. GDPR and UK GDPR additional terms
13.1 Lawful basis for processing
If you are located in the European Union or the United Kingdom, we process personal information only where we have a lawful basis to do so. Our lawful basis depends on the personal information collected and the context in which we collect it. Generally, we process personal information:
- with your consent;
- where processing is necessary for the performance of a contract to which you are party, or to take steps at your request before entering into a contract;
- where processing is necessary for the purposes of our legitimate interests, such as improving our services, securing our systems and communicating with customers, except where those interests are overridden by your interests or fundamental rights and freedoms; and
- where processing is necessary for compliance with applicable laws.
Where we process personal information based on your consent, you may withdraw that consent at any time.
13.2 Your rights under the GDPR and UK GDPR
If you are located in the EU or the UK, your rights in relation to your personal information include:
- right of access: if you ask us, we will confirm whether we are processing your personal information and provide you with a copy of it;
- right to rectification: if the personal information we hold about you is inaccurate or incomplete, you have the right to have it rectified or completed, and where we have shared it with any third party we will tell them about the rectification where possible;
- right to erasure: when your personal information is no longer needed for the purposes for which you provided it, we will delete it. You may request deletion, and we will comply unless deletion would contravene applicable law. Where we have shared the information with third parties, we will take reasonable steps to inform them of the deletion;
- right to withdraw consent: where the basis of our processing is consent, you can withdraw that consent at any time;
- right to restrict processing: you may ask us to restrict or block the processing of your personal information in certain circumstances, and where we have shared it with third parties we will tell them about the request where possible;
- right to object to processing: you may ask us to stop processing your personal information, and we will do so to the extent required by the GDPR or UK GDPR. Where personal information is processed for direct marketing, you always have the right to object, including to profiling related to direct marketing;
- rights related to automated decision-making, including profiling: you have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, except where such processing is necessary for a contract with you, authorised by law, or based on your explicit consent. We carry out automated decision-making as described in Section 4;
- right to data portability: you may obtain the personal information you have provided to us with consent or under a contract, in a commonly used, machine-readable format, and where technically feasible we will transmit it directly to another controller at your request; and
- right to complain to a supervisory authority: you can raise any concern about our privacy practices with your local data protection authority.
To exercise any of these rights, contact privacy@cradle.io. If you are not satisfied with how we deal with your request, you may refer it to your local data protection authority.
14. Changes to this policy
We may change this Privacy Policy by publishing a revised version on our website. The change applies from the date the revised policy is published. Material changes take effect in accordance with our Terms of Use.
15. Contact us
If you have any questions about this Privacy Policy or our privacy practices, or would like to request access to or correction of your personal information, contact us at:
Cookie Policy
Last updated: 4 August 2026
1. Introduction
We use cookies and similar technologies on our websites and related services. This Cookie Policy explains what cookies are, how we use them, and how you can manage your preferences.
This Cookie Policy forms part of our Privacy Policy. We use the term cookies to include similar technologies such as web beacons, clear GIFs and pixel tags.
Where required by law, we only place non-essential cookies after obtaining your consent through our cookie banner or preference tool.
2. What are cookies?
Cookies are small text files placed on your device when you visit a website. Cookies allow a website to recognise your device and store information about your preferences or past actions. They can help you navigate between pages efficiently, remember your preferences, and help make advertising you see online more relevant to you.
Cookies may be:
- session cookies, which expire when you close your browser; or
- persistent cookies, which remain until deleted or expired.
Cookies may be first-party (set by us) or third-party (set by external service providers). Third parties that place cookies on our website have their own privacy policies.
3. Types of cookies we use
3.1 Strictly necessary cookies
These cookies are essential to enable core website functionality, including security, authentication and accessibility. They do not track where else you have been on the internet and do not collect information used for marketing.
If you disable these cookies, parts of the website may not function correctly.
3.2 Functionality cookies
These cookies allow us to remember choices you make and your preferences (such as language or region) and provide enhanced features, including recognising you as a returning visitor.
They do not track your activity across other websites.
3.3 Performance and analytics cookies
These cookies collect information about how you use our websites, such as which pages are most visited and whether you receive error messages, so we can improve performance and usability. The information these cookies collect is aggregated.
Google Analytics
We use Google Analytics, a web analytics service provided by Google LLC.
Google Analytics uses cookies and similar technologies to collect information such as:
- IP address (which may be anonymised);
- browser type and version;
- pages visited and time spent;
- interaction and usage data.
The information generated by these cookies is transmitted to and stored by Google on servers in various jurisdictions. Google may process this information in accordance with its own privacy practices.
We use Google Analytics to analyse website usage, improve website performance and understand user engagement.
You can learn how Google uses data from sites that use its services here: https://policies.google.com/privacy
You can opt out of Google Analytics by installing the Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
3.4 Tag management
Google Tag Manager
We use Google Tag Manager to manage and deploy tracking and analytics tags.
Google Tag Manager does not itself collect personal information. However, it may load other tools (such as Google Analytics or advertising tags) that do collect personal information, as described in this Cookie Policy.
3.5 Marketing and advertising cookies
These cookies are used to deliver advertisements relevant to you and your interests and to measure the effectiveness of marketing campaigns. They may also be used to limit the number of times you see an advertisement.
We use these cookies for retargeting, a form of interest-based advertising that enables our advertising partners to show you advertising based on your browsing activity, including advertising to people who previously visited our website.
Google Ads and Advertising Features
We use Google Ads and Google Analytics Advertising Features, which may include:
- remarketing;
- demographic and interest reporting;
- Google Display Network (GDN) impression reporting.
These features use cookies to show ads based on your prior visits to our website.
You can opt out of personalised advertising by Google by visiting: https://adssettings.google.com
HubSpot Tracking
We use HubSpot for marketing analytics, forms and customer engagement.
HubSpot may set cookies and use tracking technologies to collect information such as:
- pages visited;
- form submissions; and
- interaction with marketing communications.
This information helps us understand how users engage with our content and improve our marketing activities.
HubSpot processes data in accordance with its Privacy Policy: https://legal.hubspot.com/privacy-policy
Reddit Ads
We use the Reddit pixel and Reddit's Conversions API to measure the effectiveness of our advertising on Reddit. With your consent to marketing cookies, we may share event information with Reddit, including your IP address, browser information, an advertising click identifier, and a hashed (pseudonymised) version of your email address or phone number where you have provided them to us. Hashing means the raw value is never sent. Reddit uses this information to match conversions to advertising and processes it in accordance with its privacy policy: https://www.reddit.com/policies/privacy-policy
LinkedIn Insight Tag
We use the LinkedIn Insight Tag to measure the effectiveness of our advertising on LinkedIn and to build advertising audiences. LinkedIn may set cookies and collect information such as your IP address, device and browser characteristics, and pages visited. LinkedIn processes data in accordance with its privacy policy: https://www.linkedin.com/legal/privacy-policy
Meta (Facebook) pixel
We use the Meta pixel to measure the effectiveness of our advertising on Facebook and Instagram. Meta may set cookies and collect information such as your IP address, browser information, and pages visited. Meta processes data in accordance with its privacy policy: https://www.facebook.com/privacy/policy
First-party advertising cookies we set
When you arrive from an advertisement, we may store the advertising click identifier from the link (for example from Google, Meta, LinkedIn, Reddit, Microsoft or TikTok advertisements) in a first-party cookie on our domain (cookie names beginning _cradle_). With your consent to marketing cookies, these identifiers are used to attribute sign-ups and purchases to the advertisement you arrived from. They are kept for up to 90 days and are not used if you decline marketing cookies.
4. How to manage or disable cookies
You can control and delete cookies as you wish. You can delete cookies already on your device, and you can set most browsers to prevent them from being placed. If you do this, you may have to manually adjust some preferences on each visit, and some parts of our websites and services may not work.
Instructions for changing browser cookie settings are available at: https://www.aboutcookies.org
You may also opt out of interest-based advertising via:
- Network Advertising Initiative: http://optout.networkadvertising.org
- Digital Advertising Alliance: http://optout.aboutads.info
- Digital Advertising Alliance AppChoices (mobile applications): http://www.aboutads.info/appchoices
- European Interactive Digital Advertising Alliance: http://www.youronlinechoices.eu
Please note that opting out of interest-based advertising does not mean you will no longer see advertising; you will continue to receive generic advertisements.
5. Third-party websites
If you follow a link from our website to a third-party website, that website will have its own cookie and privacy policies. We encourage you to review those policies before providing personal information.
6. Changes to this cookie policy
We may update this Cookie Policy from time to time. Updated versions will be published on our Website.
Version Information
Document hash: 82f154e7021eb90c21f881471b97d434cc849864c97130454daf32453b1094a4
This hash uniquely identifies this version and is recorded when you accept our terms.