Terms of Service, Acceptable Use Policy & Privacy Policy · Last updated 22 July 2026

Terms of Service

These terms govern your use of GoCushy — software operated by Daom Limited (New Zealand company no. 9403442, registered office Flat 6, 25 Broderick Road, Johnsonville, Wellington 6037, New Zealand) that lets sellers ("merchants") create checkouts, offers, and follow-up automation, operable by humans and by AI agents. By creating an account or using the service you agree to these terms.

1. What GoCushy is (and isn't)

GoCushy provides checkout and automation software. Merchants sell their own products to their own customers. Payments are processed by Stripe (or, where the merchant connects them, PayPal or Airwallex) directly into the merchant's own account — GoCushy never holds merchant or buyer funds. The merchant, not GoCushy, is the seller of record for everything sold through their checkouts and is responsible for delivering what they sell, honouring refunds, and complying with the laws that apply to their products and buyers.

2. Merchant terms

3. Fees

Plan pricing and platform fees are shown at purchase and on gocushy.com. Platform fees are collected automatically on transactions via Stripe. Stripe's own processing fees are separate and set by Stripe. Fees may change with 30 days' notice; founding-member terms are locked as sold.

4. Acceptable use

You may not use GoCushy to sell or promote:

You may not abuse the platform itself: no attempts to bypass fees, probe or attack the infrastructure, resell access without agreement, or use another merchant's data. We may suspend or terminate accounts that violate this policy, and we report unlawful activity where required.

5. Availability and changes

GoCushy is provided "as is". We work hard to keep it available and correct, but we do not guarantee uninterrupted service and may change or discontinue features with reasonable notice. We are in active development — beta features are flagged as such.

6. Liability

To the maximum extent permitted by law, Daom Limited's total liability arising from the service is limited to the fees you paid us in the 3 months before the claim. We are not liable for indirect or consequential losses, or for the acts of merchants, buyers, Stripe, or AI agents connected by users. Nothing in these terms excludes rights that cannot be excluded under the New Zealand Consumer Guarantees Act 1993 or Fair Trading Act 1986 where they apply.

7. Termination

You may close your account at any time. We may suspend or terminate accounts for breach of these terms, with notice where practicable. On termination, your Stripe account and its funds remain yours (they were never ours); export of your order data is available on request for 30 days.

8. Governing law

These terms are governed by the laws of New Zealand, and disputes are subject to the exclusive jurisdiction of the New Zealand courts.

9. Data processing (merchants)

For your buyers' personal data, you are the controller and GoCushy is your processor. GoCushy processes buyer data only to operate your checkouts, deliver receipts and access, run the automations you (or your AI, acting on your instructions) configure, and keep your sales records — never for gocushy's own purposes (no marketing, no benchmarking or analytics about you, and never to train or improve any AI model). We use the subprocessors listed in the Privacy Policy below, apply the security measures described there, notify you without undue delay of any personal-data breach affecting your buyers, and delete or return buyer data when your account closes. You are responsible for having a lawful basis for how you use buyer data downstream — in particular, sending marketing email through a connected email platform is your responsibility under the anti-spam and privacy laws that apply to you (e.g. GDPR/PECR, CAN-SPAM, the NZ Unsolicited Electronic Messages Act).

10. Support access to your account

GoCushy is run by one person — Sam Bakker. To answer support questions, investigate payment problems and fix bugs, he can open an internal admin area that shows merchant account details (name, email, business details, which payment and integration providers you have connected, and whether they're working) and order records — which include your buyers' email addresses and purchase details.

That area is read-only. Nothing in it can change, refund, delete, send, or otherwise act on your data, and there is no way to log in as you or use your account. It never shows your Stripe, PayPal, Xero or other credentials — only the provider name and whether the connection is live. Every time it is opened — the overview, a search, or an individual merchant's record — an entry is written to an activity trail recording what was viewed and when. Only the GoCushy platform account can reach it, it cannot be opened at all unless two-factor authentication is switched on for that account, and no one else has access.

What's seen there is used only to support you, to keep the platform running, and to investigate suspected fraud or abuse. We do not use your data or your buyers' data for GoCushy's own purposes — not for our marketing, not for benchmarking or analytics about you, and not to train or improve any AI model.

If we become aware of a security breach affecting your data, we'll tell you without undue delay — what we know and what we're doing about it — so you can meet your own obligations to your buyers. Where the law requires it we'll also notify the Office of the Privacy Commissioner. We notify you, not your buyers: they're your customers and that notice is yours to give, and we'll help you give it.

Privacy Policy

What we collect

How it's used

To operate checkouts, deliver receipts and follow-up automation the merchant configures, show merchants their own sales data, and (for waitlist signups) send GoCushy launch updates. We do not sell personal data.

Processors we use

Stripe (payments), Fly.io (hosting, Sydney region), and Resend (transactional email). Where a merchant connects them, data also flows to services the merchant chooses: PayPal (payments), Airwallex (payments), Xero (accounting), and their email platform (Kit, Mailchimp, ActiveCampaign, GetResponse, Drip, MailerLite, Klaviyo, Brevo, Beehiiv, Loops, Flodesk, HubSpot, or EmailOctopus). Each processes data under its own privacy terms; merchant-connected services act on the merchant's instructions.

Sending information overseas

Some processors are outside New Zealand: hosting is with Fly.io in Sydney, Australia; transactional email (Resend) and payment processing (Stripe) are in the United States. Under Information Privacy Principle 12 of the Privacy Act 2020 we disclose personal information overseas only on a permitted basis — here, each provider is bound by a data-processing agreement incorporating Standard Contractual Clauses (or equivalent) that require safeguards comparable to the Privacy Act (IPP 12(1)(f)). Where a merchant connects their own services (PayPal, Airwallex, Xero, or an email platform), those transfers are made on the merchant's instructions under the merchant's own privacy terms. Where you consent to advertising cookies on our marketing pages, Meta, Google, and TikTok (US) process that data under their own privacy terms. Information held overseas may be accessible to the courts and authorities of those countries.

Security & cards

Card numbers never touch gocushy's servers — buyers enter them directly into Stripe's (or PayPal's or Airwallex's) own embedded fields. Connected-service credentials are stored encrypted, passwords and API keys are stored hashed, and all traffic is HTTPS with HSTS.

Cookies

Essential cookies run the product: a session cookie for the dashboard, a CSRF token, a trusted-device cookie (if you enable device verification), and — where a checkout link carries a referral code — a first-party affiliate-attribution cookie set on the merchant's behalf.

Advertising & analytics cookies (Meta, Google, TikTok) are used on gocushy's own marketing pages only — the homepage, /founder, /webinar, the blog and docs — to measure our advertising and show our ads to people who visited. Where consent is required (EU/UK), nothing loads until you accept; you can change your choice any time via cookie preferences or by declining in the banner.

Merchant checkouts are different. GoCushy never places advertising or analytics trackers on merchants' checkout pages, the buyer portal, invoices, or the dashboard for gocushy's own marketing. Buyers on a merchant's checkout are the merchant's customers, and we do not track them for our benefit — the only exception is gocushy's own checkout when we sell GoCushy itself.

Trace, where a merchant has enabled it. Trace is gocushy's ad-attribution feature, which a merchant switches on for their own store. When it is on, a checkout link arriving with advertising parameters (a utm_* tag, or a click id such as fbclid or gclid) sets one first-party cookie, gc_attr_<account>, for 90 days, so the merchant can tell which of their own ads and emails produced which of their own sales. It is set on the merchant's behalf, for the merchant's reporting, under the merchant's own privacy policy — gocushy does not read it for our marketing, and it is never set on the checkouts of merchants who have not enabled Trace. A visit carrying no advertising parameters sets nothing. Buyers billed in the EU, UK or EEA — and any buyer whose country we cannot determine — are treated the same way: when the sale is recorded, the per-click advertising identifiers are dropped and only the campaign labels are kept against it, and no server-side advertising event is ever sent for that buyer. The identifiers are not used for advertising, and the cookie expires after 90 days.

Retention & deletion

Account data, order history, and the activity log are kept while the account exists (order and invoice records may be retained as long as tax law requires). Closing an account deletes its data; to close yours, email hello@gocushy.com.

Privacy breaches

If a privacy breach occurs that it is reasonable to believe has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner as soon as practicable and notify the affected individuals — or, where a merchant's buyers are affected, that merchant — as required by Part 6 of the Privacy Act 2020.

Your rights

Under the New Zealand Privacy Act 2020 (and GDPR where it applies), you can request access to or correction/deletion of your personal information: hello@gocushy.com. Buyers should contact the merchant they purchased from first, as the merchant controls their customer relationship.

Privacy Officer & complaints

Our Privacy Officer (Privacy Act 2020, s 201) is Dan Kung, reachable at privacy@communi.com for access and correction requests and any privacy concern. If we can't resolve your complaint, you can complain to the Office of the Privacy Commissioner (privacy.org.nz, 0800 803 909), which may refer unresolved matters to the Human Rights Review Tribunal.

Questions about any of this: hello@gocushy.com